Adds docs/production/README.md with single-VPS and multi-VPS deployment patterns, reverse proxy + TLS baseline, secrets strategy, and ops checklist.
- backend: copy dependency lockfiles from backend/ when build context is repo root - frontend: don't copy public/ when it doesn't exist