confluence-doc is provisioned (OAuth 2.0 service-account creds in ~/secrev.env +
PAGE_MAP_FILE from the live IT space). Drop it from COORDINATOR_SKIP_ROLES (now
just aws-posture) and add Environment=PAGE_MAP_FILE. Verified live on the box:
'Confluence API: oauth auth ready', 21 recommend-only doc gaps reported (D7, no
writes). aws-posture stays skipped (IAM/step-ca not stood up).