Switch install-script API keys to single-instance bootstrap-key pattern
Summary
Phase 3 of the bootstrap-key redesign. Depends on PR #335 (Phase 2).
Closes the "DB accumulates one row per install-script call" issue. The 1.6.x mint-per-call pattern created a fresh `user_account_api_key` row on every Add-Tentacle click. New pattern: canonical stable description + `FindApiKeyByDescriptionAsync` first, mint only on first install or after rotation.
`TentacleBootstrapKeyDescription` + `KubernetesAgentBootstrapKeyDescription` are `internal const string` pins consumed by Phase 4's rotation endpoint.
Adds `IAccountService.FindApiKeyByDescriptionAsync` returning the new internal `ApiKeyWithSecret` record (raw key value -- trusted-Core-only, never exposed via controllers).
Test plan
-
Unit: 5236/5236 pass -
6 new tests: Find/SharedKey/NoSharedKey pins on both Tentacle + K8s paths -
Phase 4 rotation endpoint will test "after rotation, next GenerateScript call gets new key" end-to-end