Check for .git/git-crypt/keys directory which only exists after
unlock, instead of parsing git-crypt status output which shows
"encrypted:" regardless of lock state.
git-crypt status outputs " encrypted:" not "***ENCRYPTED***".
The shared docker network is created by nginx's compose file, so
pre-creating it caused a label mismatch that prevented containers
from starting.
setup.sh now installs git-crypt, Bitwarden CLI, and fetches the
git-crypt key from a Bitwarden secure note. Initial setup is reduced
to just installing git, cloning, and running setup.sh.