The ACL now discovers those URLs itself (S-27), so no stack captures/injects them:
docker-compose.yml/.local.yml carry ZaaktypeIdentificatie/InformatieobjecttypeOmschrijving
instead of placeholder URLs, run-domain-check.sh + local-seed stop emitting the URLs, and
the local acl.env shrinks to the OpenZaak base URL. That base URL injection stays: OpenZaak
rejects a single-label host on zaak-create (confirmed), so the ACL is still pointed at the
container IP. ADR-0021 + demo-script note.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>