The named Docker volume mounted at /app/projects is created by Docker
as root before the container starts, so the image's build-time chown
never applies to it. A root-owned volume made the app (running as the
non-root forge user) unable to write new game folders in production.
Add an entrypoint that chowns /app/projects to forge at each startup,
then drops privileges before exec'ing gunicorn.