Split the monolithic docker-build/release/test workflows into the shared
_ci-common.yaml + trigger-specific files used on web/mydl:
- pr.yaml -> PR checks (hadolint + build smoke test)
- main.yaml -> CI + local build + git semver tag (PAT, triggers tag.yaml)
- tag.yaml -> CI + build/push :vX.Y.Z and :vX.Y.Z-latest (sole Docker push)
- cron.yaml -> nightly rebuild of :vX.Y.Z-latest
- _ci-common.yaml -> hadolint + build-test with docker smoke and GHA cache
Docker pushes to :latest on every merge are replaced by versioned,
tested tags. The tag job uses SA_TOKEN_ACTION_PUSH_TAGS (a PAT) so the
tag push actually triggers tag.yaml - GITHUB_TOKEN would not.