The documented flow started web (with Solid Queue in Puma) before the
databases existed, and required manually creating the 389ds back-end
and seeding the LDAP directory and databases. Automate it:
- add an ldap-init one-shot service that creates the 389ds back-end if
it does not exist
- add a web entrypoint that seeds LDAP and the databases on first start,
and runs db:prepare on later boots
- update README and AGENTS accordingly, including the reset steps