Add admin endpoint to rotate shared bootstrap API keys
Summary
Phase 4 of the bootstrap-key redesign. Re-filed after PR #337 was auto-closed when its base (PR #339, Phase 3) merged.
Endpoint `POST /system/bootstrap-keys/rotate` lets System Administrators invalidate the shared bootstrap key (Tentacle or KubernetesAgent surface) on suspicion of leak. Body: `{ "surface": "Tentacle" | "KubernetesAgent" }` (case-insensitive). Response: `{ description, disabledCount }`.
Already-registered agents are unaffected -- they use machine identity + server thumbprint, not the bootstrap key. Rotation only invalidates future install-script generations.
`IAccountService.DisableApiKeysByDescriptionAsync` disables every active key matching the canonical description and invalidates the API-key cache.
Test plan
-
Unit: 5241/5241 pass (5 new handler tests covering surface mapping, case-insensitivity, first-ever-rotation, unknown surface error) -
Integration: `BootstrapKeyRotation_EndToEnd_FindAfterDisable_ReturnsNull` walks the full mint → disable → find=null DB path via IRepository (bypasses IUserTokenService DI requirement) -
CI on predecessor PR (#337) was fully green (9/9) before re-target