sed -i renames the inode over the target which fails with
"Device or resource busy" on a Docker bind-mounted single file
(the zero-repo GHCR deploy mode: ./backend.env:/app/.env). Switch
to mktemp + cat write-back: only the content is written through
the mount, no rename — works in both bind-mount and regular cases,
and the host backend.env still gets the persisted key.
Simplify runtime configuration and remove legacy database and settings surface so new installs are easier to operate.
Refresh deployment assets, docs, and order execution behavior to keep the packaged app aligned with the current backend.
Made-with: Cursor