Tests, written before the change: a PIXA_ variable that is not a
setting's variable aborts startup naming it, and PIXA_PORT aborts with a
message saying to use PORT. Both fail until the change lands. The test
that sets every setting's variable now also sets PIXA_CONFIG_PATH, so it
shows that none of those names is rejected.
Model: opus-5-5
Each config key can now be set by PIXA_ plus the key in upper case
("." written as "_"), and the port by PORT. A present variable, even
an empty one, is read before the config file through the existing
typed getters, so every existing check covers it; errors name the key
and the variable, never the signing key or metrics password. A
variable named in the file's env: section overrides both. An empty
string for blocked_networks or trusted_proxies is now an empty list.
The image no longer bakes in config.docker.yml or passes --config; its
HEALTHCHECK probes ${PORT:-8080}. The config file is looked for under
/etc/pixa rather than /etc/pixad. Also covers #99.
Model: opus-5-5