- Add snat/masquerade, netmap, and 1:1 nat as stored, terraformable resources:
migration 0003, model types, store CRUD (id-keyed, generation-bumping), and
REST handlers. These are the global-intent/device-resolved NAT tier; compiler
rendering of NAT into per-device configs is a tracked follow-up.
- Add a testcontainers-backed store integration suite exercising the CRUD
lifecycle, generation bumping, source/dest grammar validation, and FK cascade
against a real Postgres. It self-skips under 'go test -short' (the CI path) so
a container runtime is only needed for the full run.