95a8dbcea9
#151: Broker gains uriEnv beside uri, taking the AMQP URI from an env var so the password stays out of fleetd.yaml (same pattern as auth.tokenEnv). uriEnv wins when set; isConfigured() treats a uriEnv naming an unset/blank variable as unconfigured. A configured uriEnv is added to the startup required-secrets report. Never logs the resolved URI (it carries the password). #152: AmqpReplyInbox.open throwing at boot no longer stops the daemon. The selection at the call site catches the failure and falls back to the in-memory inbox for the process lifetime, warning loudly that durable cross-restart delivery is off and logging the failed URI with credentials stripped.