0cca3730fb
The installer is meant to be run by CI/CD with no human writes on prod, so updates should mirror the repo exactly rather than refuse on local drift: - Replace `git pull --ff-only` with fetch + `checkout -B origin/$BRANCH` + `reset --hard` + `clean -fd` so the box always matches origin/$BRANCH. - Set GIT_TERMINAL_PROMPT=0 so a missing/expired credential fails fast in CI instead of hanging on a prompt. - npm ci --omit=dev (lockfile, production-only) with a plain-install fallback. - Allow REPO_URL / REPO_DIR / BRANCH to be overridden from the environment. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>