Caddy served all of /opt/webtrees through file_server, so media under
data/media could be fetched by URL without passing webtrees' privacy rules.
webtrees only protects data/ with an .htaccess, which Caddy ignores. Deny the
folders webtrees' own nginx guide keeps private, plus dotfiles.
update_script adds the rule to existing Caddyfiles on every update, not only
when a new release is out, and keeps the old file if the result fails
caddy validate.
Replaces the misc/build.func bootstrap with the two-root core loader.
No other change: the engine contract (var_*, update_script, start,
build_container, description) is identical on both engines.
versitygw.sh additionally gains a trailing newline; it lacked one.
With this batch every ct/ script is on the core engine.