Files
hermes-agent/docker
kshitijk4poor 6cd2502629 fix(docker): stage2 routing sync removes its own lines when the platform unsets the variable
Follow-up on the sync block:

- Lines stage2 writes carry a `# stage2-managed` marker (both dotenv tokenizers drop an inline
  comment after whitespace). A boot without the variable removes only those lines, so moving an
  instance back to production no longer leaves the staging URL pinned in every .env — the mirror
  image of the quarantine the sync fixes. Hand-set lines are never touched.
- One `rewrite_env_var FILE NAME [LINE]` does the drop-then-append through the existing inode
  (owner/mode kept) and refuses to rewrite when `grep -v` could not READ the file (exit 2) —
  the old `|| true` turned a read failure into a wipe of every other secret in that .env.
- Loop per file, names inner: one symlink check and one create per .env instead of three.
- Comment keeps the WHY; tests trimmed to two contracts (land everywhere + parsed by the runtime
  tokenizer; container-wins → idempotent → removed-when-unset, symlink refused).
- The unset path drops only marked lines (an operator line beside a managed one survives); the
  set path replaces every assignment (the platform is the authority when it sets the value).
- Read-only file: warning, rc 0, file unchanged — pinned in the lifecycle test.
2026-09-16 16:17:51 +05:30
..
…