Updates encrypted environment variables. If env_keys changes for contract-owned KMS, requires two-phase flow with on-chain hash registration.
Encrypted env blob as hex string
Allowed env var names. Changes trigger verification for contract-owned KMS.
Hash from Phase 1 response (Phase 2 only)
Transaction hash proving on-chain registration (Phase 2 only)
Update initiated, returns correlation_id and allowed_envs_changed flag