- Multi-stage Dockerfile (Node 22 alpine, BuildKit cache, non-root user).
HEALTHCHECK and metrics port (9090) deferred until task 1.10 ships;
comments document the resume.
- .gitea/workflows/build.yml — single build job following the pattern
of other TRM repos (no services/container, ubuntu-latest direct).
Tests + typecheck + lint inline; image tagged :main.
- compose.dev.yaml — local-build variant for verifying Dockerfile
changes pre-push. Production deploy lives in the sibling deploy/ repo.
- .env.example documenting all runtime env vars.
- README updated to point at deploy/ for production and explain CI.
- Task 1.11 marked done (slim variant) in ROADMAP and task file.