Add a single-secret counterpart to reprovision_from_secret's restore-all:
update ONE egress token for a running bottle without a relaunch, for
refreshing a short-lived host credential (e.g. the Codex access token)
whose launch-time snapshot has expired.
- registry_store.store_agent_secret: per-key upsert (delete+insert of the
one row), the counterpart of store_agent_secrets' replace-all.
- OrchestratorCore.update_agent_secret: set the in-memory token AND upsert
the re-encrypted row under the bottle's env_var_secret, leaving other
tokens untouched.
- POST /bottles/<id>/secret (cli-only) + client.update_agent_secret.
Refs #510, #512
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>