Keep module expansion inside the container shell when probing Python imports, preventing set -u from failing in the host script.
Add Dockerfile boundary checks and deployable image purity validation for backend/frontend runtime artifacts. Wire enforcement into CI workflows and document runtime-vs-validation ownership.