Traefik has no certificate resolver named 'letsencrypt' configured (this
cluster terminates TLS at Cloudflare and uses Traefik's default cert via
the websecure entrypoint, matching every other neuron-prod IngressRoute).
The invalid certResolver caused Traefik to refuse the router with:
ERR Router uses a nonexistent certificate resolver
certificateResolver=letsencrypt routerName=neuron-prod-dharma-...
so requests to dharma.neurontechnologies.ai/health surfaced as 502 from
Cloudflare even though the dharma pod was healthy on :8765.