Switch install-script API keys to single-instance bootstrap-key pattern
Summary
Phase 3 of the bootstrap-key redesign. Re-filed after PR #336 was auto-closed when its base (PR #338, Phase 2) merged.
Closes the "DB accumulates one row per install-script call" issue. The 1.6.x mint-per-call pattern created a fresh `user_account_api_key` row on every Add-Tentacle click. New pattern: canonical stable description + `FindApiKeyByDescriptionAsync` first, mint only on first install or after rotation.
`TentacleBootstrapKeyDescription` + `KubernetesAgentBootstrapKeyDescription` are public consts consumed by Phase 4's rotation endpoint.
Adds `IAccountService.FindApiKeyByDescriptionAsync` returning the new internal `ApiKeyWithSecret` record (raw key value -- trusted-Core-only, never exposed via controllers).
Test plan
-
Unit: 5236/5236 pass -
6 new tests: Find/SharedKey/NoSharedKey pins on both Tentacle + K8s paths -
CI on the predecessor PR (#336) was fully green (9/9) before re-target