.dockerignore now lists every .gitignore pattern, each with **/ so Docker
matches it in every directory as git does, plus the top-level data/
directory. git-ignored secrets such as .env.local, *.key files and
data/session.key no longer reach the build stages or the build cache. .git
stays in the context and no tracked file is listed, so the version still
comes from git describe without -dirty.
data/, where upaasd keeps its database and session key when run from the
checkout, is now git-ignored.
Model: opus-5-5