Lists all containers without LAN-published ports across CT 104/105/109/110/111/112/113. Recommends keep-internal vs expose for each. Confirms the public/LAN/docker-internal tiering is clean across the fleet.