All 5 CronJob manifests referenced 'myorg-assistant:latest' with
imagePullPolicy: IfNotPresent, but that image was never pushed to any
registry. The Deployment already uses the correct registry image
(git.rogi.casa/roger/myorg-assistant/myorg-assistant:fcf79bf), so the
CronJob pods were stuck in ImagePullBackOff indefinitely.
Fix: use the same registry image + imagePullPolicy: Always.
CronJobs were referencing 'myorg-assistant:latest' (a local image that
doesn't exist in the cluster), causing ImagePullBackOff on all 4 active
CronJob pods. Updated all 5 CronJob manifests to use the same image as
the Deployment (git.rogi.casa/roger/myorg-assistant/myorg-assistant:fcf79bf)
and added imagePullSecrets: gitea-registry for authentication.
The ingresses referenced a Cloudflare OriginIssuer 'prod-issuer' whose CRD
and controller are not installed in the cluster, so cert-manager could not
issue certs and Traefik served a default cert (invalid SSL). Switch to the
existing letsencrypt-prod ClusterIssuer with specific hostnames + per-app
secrets, matching the working ingresses (http-01 cannot issue wildcards).