# All images build with `service/` as the build context (see compose.yaml and # service/Dockerfile*). Nothing in the repo root is COPY'd into an image, so # deny everything. Use service/.dockerignore for per-image context filtering. *