Stop pinning the Go toolchain; install it on the host on demand
deploy.sh no longer hardcodes GO_VERSION. Go's own selection rule
(GOTOOLCHAIN=auto) chooses the toolchain for the target commit: the
caller's installed Go, or a newer release when go.mod requires one. The
selected version is validated, reported, held with GOTOOLCHAIN=local for
every later step, and recorded in the release metadata as before.
The remote build installs a missing toolchain from the official
distribution, verified against its published sha256, into a staging
directory that is normalized and version-checked before an atomic move
into /opt/joedistilled/toolchains/<version>. Partial directories fail
closed and are cleaned up.
Update the deployment and design docs and add test coverage for the
unpinned selection and on-demand install.