Add entrypoint.sh that fetches secrets from Infisical at container
startup. GEMINI_API_KEY, RUNPOD_API_KEY, and FAL_KEY now come from
Infisical instead of being passed directly in docker-compose.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>