Tests, written before the change, for the check of PIXA_ names at
startup: a PIXA_ variable that is not a setting's variable aborts naming
it, PIXA_PORT aborts with a message saying to use PORT, and
PIXA_CONFIG_PATH and every setting's variable are accepted. They call
validateKnownEnvVars, which the change adds, so the package does not
build until it lands.
Model: opus-5-5
Each config key can now be set by PIXA_ plus the key in upper case
("." written as "_"), and the port by PORT. A present variable, even
an empty one, is read before the config file through the existing
typed getters, so every existing check covers it; errors name the key
and the variable, never the signing key or metrics password. A
variable named in the file's env: section overrides both. An empty
string for blocked_networks or trusted_proxies is now an empty list.
The image no longer bakes in config.docker.yml or passes --config; its
HEALTHCHECK probes ${PORT:-8080}. The config file is looked for under
/etc/pixa rather than /etc/pixad. Also covers #99.
Model: opus-5-5