Add apps/scheduler/Dockerfile, an optional profile-gated `scheduler` service in docker-compose, and SCHEDULER_IMAGE/PORT/DEMO_MODE examples in portainer.env.example. The service stays off by default (scheduler profile) and SCHEDULER_DEMO_MODE defaults to 0 so the Authentik login is never bypassed in production.