The compose file builds the image from this repo, mounts the Docker
socket and HOST_DATA_DIR (passed to upaas as UPAAS_HOST_DATA_DIR),
reads settings from .env, and restarts unless stopped. The port is
published on 127.0.0.1 only, for a TLS-terminating proxy in front, and
UPAAS_PLAINTEXT_HTTP is left unset. A healthcheck against /health uses
the runtime image's busybox wget.
The README's plain-HTTP Compose example becomes a short deploy section
that points at the file. .env is added to .dockerignore so settings are
not copied into the build.
Model: opus-5-5