I agree, and I do (if I end up actually keeping a piece of software running).
It's also quite likely that a pre-built docker image isn't going to satisfy everyone's deployment requirements.
Starting out with a philosophy that you'll make all the configuration and security choices for every user of your project isn't a great start, and that's how I read all these hard-coded assumptions.