Regenerated from the fixed apps/nginx-proxy-manager/manifest.yml (the only semantic change vs the previous signed catalog) and signed with the release-root key. Catalog-covered nodes pick this up on their next hourly fetch and the NPM start/die loop ends: s6 gets its /etc/letsencrypt mount back and the internal nginx can bind 80/443/81 again under --cap-drop=ALL.