Python Apps publish with server-managed membership

Python Apps now request membership through admission, which checks the App and project permissions before assigning ownership. Function calls receive their App and Function labels automatically, including batched calls. Inline Secrets are removed with their App; shared built Images remain available.