The build order starts with milestone 1 and milestone 2, then keeps the
earlier stages in their order, less what the two milestones build.
Milestone 2 builds the container image with runit and the health check,
so it answers /_smallwebwaf/healthz before the other admin endpoints.
The four body-size settings become SWWAF_REQUEST_MAX_BYTES and
SWWAF_RESPONSE_MAX_BYTES, since bodies pass through unchanged; the four
timeouts stay.
GeoJS answers are kept in memory; lookups.json comes in milestone 3 or
later, as sneak ruled.
README.md: the two sentences this change made wrong.
Model: opus-5-5