* fix(cli): generate per-install secrets instead of using fixed values
The launcher passed the same built-in BETTER_AUTH_SECRET and ENCRYPTION_KEY
to every install. Generate them once per install, persist them 0600 at
~/.simstudio/secrets.env, and reuse them on later runs so data already in
the Postgres volume stays readable.
Also passes INTERNAL_API_SECRET, which the realtime container requires and
never received.
* fix(cli): reassert owner-only permissions on the secrets file
writeFileSync's `mode` applies only when it creates the file, and the write
is skipped entirely when the stored values are already valid — so a secrets
file left with permissive permissions kept them. chmod it on every run.
* fix(cli): write the secrets file atomically
Regenerating any one key rewrites all of them, and a plain write truncates
first — a crash mid-rewrite would strand a still-valid ENCRYPTION_KEY and
orphan the data it protects. Write to a temp file and rename into place.