feat: add host-level WireGuard client via networking.wireguard
- Add wg0 interface config with agenix-managed secrets - Revert compose submodule to remove NET_ADMIN from Hermes - WireGuard runs at host level, all containers inherit the tunnel
This commit is contained in: