eb8ac7f011
tracker-policy-pr / check-pr (pull_request) Successful in 13s
prd-number-check / require-numbered-prds (pull_request) Successful in 22s
lint / lint (push) Failing after 1m1s
test / unit (pull_request) Successful in 54s
test / integration-docker (pull_request) Successful in 1m6s
test / coverage (pull_request) Successful in 16s
Add a single-secret counterpart to reprovision_from_secret's restore-all: update ONE egress token for a running bottle without a relaunch, for refreshing a short-lived host credential (e.g. the Codex access token) whose launch-time snapshot has expired. - registry_store.store_agent_secret: per-key upsert (delete+insert of the one row), the counterpart of store_agent_secrets' replace-all. - OrchestratorCore.update_agent_secret: set the in-memory token AND upsert the re-encrypted row under the bottle's env_var_secret, leaving other tokens untouched. - POST /bottles/<id>/secret (cli-only) + client.update_agent_secret. Refs #510, #512 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>