Server, edge, and client instrumentation wired up via SENTRY_DSN / NEXT_PUBLIC_SENTRY_DSN. Fully inert without a DSN configured (verified with a clean local build + full test suite) — safe to ship ahead of actually having a Sentry project. Source-map upload is opt-in via SENTRY_AUTH_TOKEN (kept out of the Docker build-arg chain since build args land in image layer history; only the public DSN is a build arg).