After the theme, I kept going on lerd. This is what landed since.
Secrets that never touch the disk
A project can now name an env_provider in .lerd.yaml, a command that prints
dotenv lines, such as infisical export --format=dotenv. lerd runs it behind
its consent prompt and writes the output to tmpfs with mode 0600, so the values
never land in .env or in container storage. PHP-FPM, the queue workers and
lerd artisan all load them, each for its own site
(PR #2069).
Every site shares one FPM pool, so I tested for bleed rather than assume there was none: two sites with the same key set to different values, 4000 concurrent requests alternating between them, every worker serving both. Neither site saw the other's value.
A reboot empties tmpfs, and systemd brings FPM back without running the providers again. The watcher now refills them when it starts (PR #2148).
One request, start to finish
While debug capture is on, every response carries a request id that nginx logs and the PHP side stamps on what it records. A recent request gets an Inspect button that opens a timeline of its queries, views, cache and HTTP calls, jobs, logs and exceptions, on the time nginx measured. The browser's errors attach to the same id, so does an SPX profile, and an assistant can read the same request over MCP (PR #2150).
Capturing the browser side came first. A script injected through nginx, off until you switch it on, reports uncaught errors, failed requests, console messages and page views to the dashboard, with presets for the events Inertia, Turbo, htmx and Vite report through (PR #2123, frameworks #96). And a file path in the dashboard now opens in the editor you pick, VS Code, PhpStorm, Zed and others (PR #2122).