* refactor(credentials): derive rpc secret and remove iam keygen * fix(credentials): reject default access key RPC secret * test(credentials): align RPC fallback and add keygen coverage
Co-authored-by: Copilot <[email protected]> Co-authored-by: houseme <[email protected]>