Extend the pre-commit secret-scan to catch environment-specific values (*.ts.net MagicDNS names and 100.64.0.0/10 tailnet IPs) so live infra can't be committed into code, docs, or examples. Verified: detects leaks, no false positive on 192.0.2.x or non-CGNAT 100.x, and the script does not self-trip.