6e9a9aa41b
- CLAUDE.md: Add "DB Secret Management" section documenting the incident, the root cause (stale password baked into appsettings.Production.json, real password only ever lived in /home/kjh2064/.config/quantengine.env, never wired into systemd), and the permanent fix (EnvironmentFile= drop-in, applied by hand on 2026-07-12 with 'sudo systemctl restart quantengine' verified active and journalctl clean). - CLAUDE.md: Refresh the stale "Gitea Actions Workflows" section (was still describing an on:push deploy-prod.yml with a single Build stage; now lists prepare-release.yml + deploy-prod.yml correctly as workflow_dispatch-only, 6-point health check). - deploy-prod.yml: Add Check 6 (DB authentication) to the health check step. The existing checks only hit GET /Account/Login, which returns HTTP 200 even when ConnectionStrings is broken -- that's exactly why tonight's outage passed every prior health check. The new check greps journalctl for '28P01'/'password authentication failed' in the minute after restart and fails the deployment if found, so a broken DB connection string can no longer masquerade as a successful deploy.