Adding a project to the pipeline today is an operator editing the gitwatcher's config.yaml on the node (a watches: entry with name/repo/ref + scale_name/domain/port/health_path/disk_path/node) and restarting the scale. Make it self-service: a creator enrols a repo through hydramancer (repo URL + scale name/domain/port/disk), which registers the watch (via a watcher admin API, or a shared watch registry the gitwatcher reads) and provisions the domain, without a human editing files on a node. This is the step that turns the pipeline from operator-onboarded into genuinely self-serve. Related: #508; the hydramancer /deploy entry + onboarding doc already exist.