The v5 rewrite gates AI features behind two new env vars we never had.
Opening the AI Integrations tab calls aiProviders.list, which runs
assertCredentialEncryptionConfigured() and throws
AI_CREDENTIAL_ENCRYPTION_UNAVAILABLE when ENCRYPTION_SECRET is unset --
so the tab errored on mount instead of rendering.
The agent workspace has a second gate: isAgentEnvironmentConfigured()
requires ENCRYPTION_SECRET *and* REDIS_URL, so add a dedicated redis to
the stack rather than leaving the agent half-broken. Every other redis
on the host is on another stack's private network.
ENCRYPTION_SECRET encrypts stored provider API keys at rest (schema
requires >=32 chars); rotating it makes saved keys undecryptable, so
it is pinned like AUTH_SECRET.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>