Covers the published amd64/arm64 image with Compose and with plain
docker run, when to build your own instead, and fetching
egress-lockdown.sh on its own.
The build stage runs on the build platform and cross-compiles for the
target, so arm64 needs no emulation. The configuration check runs a
native build, since the target binary may not run on the builder.
Accepts mail for an allowlist of domains from allowlisted client networks
and discards it on receipt. No outbound code, no logging, scratch image;
all settings are Dockerfile build arguments compiled into the binary.