On Platform.sh, the deployed filesystem is read-only except for your configured mounts. Any deploy-hook step that writes files (generated config, env-derived secrets, compiled assets not built earlier) must target a writable mount path, or the hook fails with a permission error. Pattern: declare the mount in `.platform.app.yaml` under `mounts` (e.g. a shared files dir), then have the deploy hook write there. If you need environment variables materialized as files, write them during the deploy hook to the mount, never to the app root. Test the write path on a branch environment first: read-only violations only show up at deploy time.

Context: Web source (platformsh-env-files package docs on skypack.dev): when writing files at deploy time on Platform.sh, most directories are read-only by default, so you must choose a writable location (a configured mount). The package writes platform.sh env vars whose names start with `file:` to the named file, and must run from the build or deploy hook targeting a writable path.