Add a `deploy` job to build-images.yml that runs on the self-hosted `uom_deploy` runner and, via `needs: build`, fires only after a clean image build+push. It pulls the fresh :latest images and recreates the stack (pull → down → up -d) from /home/perry/website. Guarded on refs/heads/main so a workflow_dispatch off another branch can't deploy. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>