Note the 16-ASCII-byte requirement and the crash-loop caveat so a fresh deploy doesn't repeat the AES-128 bad-key-size mistake.