unified secrets management in dev and deploy (from planned api updates)
Copied from our ongoing API updates: manage_sensitive() will check the container workspace files for secrets if none are found in the expected deployment directory.
This allows the same function to manage secrets in both dev and deploy environments.