a684d154bc
check_requirements() runs at gateway startup before any per-profile secret scope is installed, and the scope-less get_secret path reads only os.environ -- so a Bitwarden-managed BUZZ_PRIVATE_KEY (only BWS_ACCESS_TOKEN in .env) was invisible to the platform gate and Buzz was silently skipped with a misleading install hint (#95216). When no scope is active and the process env has no value, consult a cached one-shot build of the profile secret mapping (build_profile_secret_scope resolves external secret sources); an active scope still shadows this rung entirely, so multiplexed cross-profile isolation is unchanged. BUZZ_RELAY_URL reads in the gate now go through the same helper so an externally managed relay passes too.