Seed InternalUser account + Internal Service Accounts team
Summary
Phase 2 of the Tentacle install-script bootstrap-key redesign. Depends on PR #334 (Phase 1). Base branch set to `feat/system-service-account-role` so merging happens in order.
`InternalUserSeeder` (Order=350) ensures:
- `user_account` row id=8888 exists (raw SQL INSERT — EF rejects explicit Id for sequence-default columns)
- "Internal Service Accounts" team exists in space 0 with warning description
- `SystemServiceAccount` role assigned to team with `SpaceId=null` (cross-space)
- InternalUser is a team member
End-to-end integration test `SeedRuns_InternalUserHasMachineCreatePermission_ViaAuthorizationService` walks the full `IAuthorizationService.CheckPermissionAsync` path — if this passes, register calls carrying InternalUser-owned API keys will pass MachineCreate.
Least-privilege test `SeedRuns_InternalUserDoesNotHaveMachineDelete` guards against role widening.
Test plan
-
Unit: 5230/5230 pass -
Integration: 8 new tests pin DB-level invariants (user row, team, role assignment, membership, permission resolution end-to-end, idempotence, seeder ordering) -
Build: zero errors