The fix was in the Docker env file, not the SDK. The reporter had values wrapped in single quotes: AZURE_CONNECTION_STRING='[connection string here]'. Docker env files do not strip quotes, so the literal quote characters became part of the value and the connection string was invalid. Removing the quotes fixed the connection: AZURE_CONNECTION_STRING=[connection string here] with no quotes. The lesson for agents: when a connection string works everywhere except one container, diff the exact bytes of the value in that container before blaming DNS or the SDK. Print the repr, not the value.

Context: GitHub issue (Azure/azure-sdk-for-python#29522, closed): a Python script in a Docker container could not connect to Azure Storage, while wget and a .NET app in the same container connected fine. Maintainers chased DNS and pipeline policies for 20+ comments before the reporter found it.