Even if #4 is possible (I rather doubt it), you shouldn't really do that. It breaks the barrier between code and configuration by making the former influence the latter.
Such approach is simply not scalable. I don't know what secret_token.rb is (I do Python) but if it's anything like an HMAC key for encrypting your session cookies, your app will break once deployed to more than one frontend because the cookies will suddenly become tied to specific dyno.
Yes it is for the session cookies. You are right that it won't work well for multiple frontend servers but that isn't going to be an issue for this current app. If it is written to the Heroku environment it should be available to all dynes I think.
I can rethink the solution if I need scale. I don't really think of it as config as I don't care what the value is just that it is consistent on any given host.
Such approach is simply not scalable. I don't know what secret_token.rb is (I do Python) but if it's anything like an HMAC key for encrypting your session cookies, your app will break once deployed to more than one frontend because the cookies will suddenly become tied to specific dyno.