Both use an allowlist so only the files each Dockerfile copies are sent to the build context. For caddy this keeps the TLS certificates and keys in data/ and config/ out of the context; for api it skips training code, datasets, saved models and caches. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>