Build the HTTP router over db. Read endpoints take the read lock;
/ingest takes the write lock. Guards are dropped before any .await.
GET /watch upgrades to a WebSocket fed by the post-commit sink.
Like router_with_ui but marks the connection as TLS-active so the auth
cookie carries the Secure attribute. Use when the binary is serving
directly over HTTPS (i.e. via serve_tls) rather than behind a proxy.