Client-side cap on a derived secret name. The BACKEND accepts up to 128
characters matching ^[A-Za-z0-9][A-Za-z0-9._-]*$
(backend/src/routes/handlers/secrets.ts), so this 63-character DNS-label
shape is a deliberately TIGHTER client convention — it is what the
template-deploy path has always minted, and it keeps derived names usable
wherever a label-shaped identifier is expected.
Client-side cap on a derived secret name. The BACKEND accepts up to 128 characters matching
^[A-Za-z0-9][A-Za-z0-9._-]*$(backend/src/routes/handlers/secrets.ts), so this 63-character DNS-label shape is a deliberately TIGHTER client convention — it is what the template-deploy path has always minted, and it keeps derived names usable wherever a label-shaped identifier is expected.