- Add Photon OCI container on nixnuc (rtuszik/photon-docker, planet
index) storing data on the /orico ZFS mirror
- Open port 2322 in nixnuc's main firewall allowlist (LAN + Tailscale)
- Remove services.nominatim, its nginx vhost, and www-data PostgreSQL
user from nixnuc
- Switch Dawarich on hetznix01 from NOMINATIM_API_HOST to
PHOTON_API_HOST pointing at nixnuc.atlas-snares.ts.net:2322
- Add zfs-datasets.nix oneshot to declaratively ensure all orico
datasets exist before services start
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>