Seed InternalUser account + Internal Service Accounts team
Summary
Phase 2 of the Tentacle install-script bootstrap-key redesign. Re-opened after PR #335 was auto-closed when its base (PR #334) merged + deleted its branch.
`InternalUserSeeder` (Order=350) ensures:
- `user_account` row id=8888 exists (raw SQL INSERT — EF rejects explicit Id for sequence-default columns)
- "Internal Service Accounts" team exists in space 0 with warning description
- `SystemServiceAccount` role assigned to team with `SpaceId=null` (cross-space)
- InternalUser is a team member
- Normalises legacy `display_name='internal_user'` (from `001_initial_schema.sql`) to canonical `'System'`
End-to-end integration test `SeedRuns_InternalUserHasMachineCreatePermission_ViaAuthorizationService` walks the full `IAuthorizationService.CheckPermissionAsync` path — if this passes, register calls carrying InternalUser-owned API keys will pass MachineCreate.
Least-privilege test `SeedRuns_InternalUserDoesNotHaveMachineDelete` guards against role widening.
Test plan
-
Unit: 5230/5230 pass -
Integration: 8 new tests pin DB-level invariants -
Build: zero errors -
CI: fix for legacy display_name normalisation merged on this branch (commit `7b67f8b6`)