Add SystemServiceAccount built-in role for bootstrap operations
Summary
Phase 1 of the Tentacle install-script bootstrap-key redesign. Adds a new built-in role `SystemServiceAccount` for the internal account that will own the shared bootstrap API key.
Permissions: `MachineView` + `MachineCreate` + `MachineEdit` only. Deliberately omits `MachineDelete` (bootstrap must not delete machines) + all deployment / account / environment / task permissions.
`BuiltInRoleDefinition` gains `IsReservedForSystem` (default false; true on the new role). `PermissionRoleResolver.GetBuiltInRolesGranting` filters reserved roles by default so operator-facing 403 hints never suggest assigning a system-reserved role to a human. An `includeSystemReserved: true` overload exposes the full list for seeders / diagnostics.
Test plan
-
Unit: 5230/5230 pass (6 new SystemServiceAccount-specific tests + filter-behavior pin) -
Build: zero errors -
Integration: Phase 2 will land the InternalUser seeder that consumes this role; integration test belongs there
Phase 2-5 of the series will land in follow-up PRs.