A plain `docker build .` now stamps the version into bsdaily: the
VERSION build argument when one is given, otherwise `git describe
--tags --always` of the .git in the build context. The build fails if
the context carries .git and no version comes out. A host `make` build
stamps the same `git describe` value, or dev when it yields nothing.
bsdaily logs the version on the first line of every run and prints it
with --version.
The new .dockerignore is the canonical copy, which keeps .git/config
out of the build context, plus this repo's host-built artifacts.
script/docker is replaced with the canonical copy, which passes the
version it derives on the host.
Model: opus-5-5
Add a detailed README, WTFPL LICENSE, and build/CI tooling modeled on
the vaultik repo (Makefile, multi-stage digest-pinned Dockerfile,
.gitea/workflows/check.yml). Bump Go to 1.26.4 and pin golangci-lint
to v2.12.2. gofmt existing sources so the new fmt-check gate passes.