0600. Gemini credentials and the scoped Doppler service token do not enter Git, Compose YAML, browser code, logs, or documentation. The refresh operation retrieves the needed provider credential non-echoingly into the existing secret mechanism.
A generated bootstrap credential set was exposed during internal Compose inspection in Phase 4. It was immediately rotated, the empty bootstrap database recreated, and no provider key was involved. A later malformed/diagnostic Doppler token was revoked before Hostinger use. These incidents are closed remediation records, not active secrets.Operations
Secrets
Server-side secret injection and safe verification practices.
The application uses an external server-side secret file with mode