Ancillary operations and opt-in test controls

CapabilityEnvironment variables
Operator-local DNSimple CLISee the operator-shell list below; never store it in a deployment config
GitHub release authenticationGITHUB_TOKEN
Xero sandbox OAuthXERO_SANDBOX_CLIENT_ID, XERO_SANDBOX_CLIENT_SECRET
Engineering Slack routingSLACK_OPS_MENTION
Browser-driver overrideWEBDRIVER_URL, WEBDRIVER_HEADED
Deterministic GCP test tokenDEVX_GCP_FAKE_TOKEN, ARCHIVES_FAKE_TOKEN
Browser gateNAV_REQUIRE_HARNESS, NAV_REASK_SHOTS
Server-mode store laneNAV_REQUIRE_SURREAL

The DNSimple CLI transaction uses operator-shell variables DNS_SIMPLE (or legacy DNSIMPLE_API_TOKEN), DNSIMPLE_TOKEN, DNS_ACCT, and DNS_ZONE. None belongs in a deployment config.