Onboard a locally-hosted service into Peggy — expose an app running on the home Mac at a public, Google-authenticated HTTPS URL (e.g. https://peggy.fly.dev/<name>/) over Fly's WireGuard mesh, with no open ports and no client VPN. Use when the user runs `/peggy`, or asks to "onboard/expose/publish this service via Peggy", "put this app behind Peggy", "register this with the gateway", or "make this reachable from my phone through Peggy". Handles 6PN binding, path-prefix correctness, registration via the `peggy` CLI (or SDK/LaunchDaemon), and fail-closed verification.