Changed E2E_SSH_KEY and E2E_DNS_ZONE from secrets.* to vars.*. The token stays as a secret since it's the only actual sensitive value. This also explains why those two were empty in the logs — secrets values are masked, but since they weren't found in secrets they resolved to empty strings, while vars values would have been printed (and populated).