The build order starts with milestone 1 and milestone 2, then keeps the
earlier stages in their order, less what the two milestones build.
Milestone 2 builds the container image with runit and the health check,
so it answers /_smallwebwaf/healthz before the other admin endpoints.
The four body-size settings become SWWAF_REQUEST_MAX_BYTES and
SWWAF_RESPONSE_MAX_BYTES, since bodies pass through unchanged; the four
timeouts stay.
GeoJS answers are kept in memory; lookups.json comes in milestone 3 or
later, as sneak ruled.
README.md: the two sentences this change made wrong.
Model: opus-5-5
Initial documents: what smallwebwaf is and why, the proposed feature list, the design spec with the rule file format and the open design questions, and the survey of existing tools.
Model: fable-5-1