Hosted deploys set HERMES_PORTAL_BASE_URL and NOUS_INFERENCE_BASE_URL only in the
container environment and run the gateway with GATEWAY_MULTIPLEX_PROFILES=true.
Since #108319 / #111809 both are resolved through the profile secret scope, which
is built from <profile>/.env and never falls back to os.environ, so on every
routed turn the override is absent: the Portal allowlist heals the URL to
production, the staging refresh token is POSTed to portal.nousresearch.com, the
Portal answers invalid_grant, and the Nous login is quarantined ~10s after boot
("No access token found for Nous Portal login"). Observed live on
hermes-agent-stg-gg-probe-test-0062: 7 rebootstrap/quarantine cycles in one
night, auth.json 5223 -> 714 bytes each time.
stage2 now syncs both variables from the container env into $HERMES_HOME/.env and
every profiles/*/.env (created 0600 hermes-owned when missing), replacing a stale
line rather than adding a second assignment, skipping files that already carry
the value, refusing symlinked paths, and degrading to a warning on a read-only
volume. Files are untouched when the variable is not set.
Three invariant tests run the block under `set -eu` with sh; also exercised
under busybox sh.