e5167729a8
docker-compose.multisite-e2e.yml boots two full all-in-one instances (master + spoke, each with bundled slapd) and a client that drives the actual HTTP API: seeds admins, mints a join key, joins the spoke, and verifies the spoke persisted its role across restart, adopted the pre-join catalog, is enforced read-only, and reports WAN health. Verified passing locally. Existing docker-compose.test.yml/e2e.yml split ldap+redis+app into separate containers, which doesn't work here -- POST /api/site/export runs slapcat in-process, so master and spoke each need their own bundled slapd (Dockerfile.openldap), not a shared one.