Adds portal-frontend as a new service (no published port, only reachable via the proxy, same as new-frontend) and two nginx location blocks for /portal - a bare-path redirect plus the prefix-stripping proxy_pass. The existing /, /legacy, and /api/ blocks are unchanged. Verified end to end: /portal/, a deep link, and / all return 200 through the single published proxy port, and /api/worklist still returns the full 17-item worklist.