04a8b907

By: Michael Lynch <git@mtlynch.io>

Replace production databases with or without a Fly volume

Backport the upload safeguards from refactoring-english-webhooks commits
 df7a6a7, a342b16, and 460337d. Uploading a Litestream snapshot alone does
not replace a database that survives on the machine because the entrypoint
only restores when the database is absent.

Disable the app during replacement, clear the old database and Litestream
state, then restore the original entrypoint and wait for machine and app
readiness. Accept already-absent files on ephemeral storage rather than
requiring a mounted volume or a separate workflow. Check remote exit codes
so failed deletion or inspection cannot report success.

Keep failed replacements disabled, print the original init settings for
recovery, and reject retries that would preserve the temporary sleep
entrypoint. Add jq and GNU coreutils for machine JSON and bounded health
requests, plus an offline regression target covering both storage cases
and failure paths.

Live Fly startup and restoration remain unverified because this environment
has no production credentials.
configuredevShellx86_64-linuxcheck-bashcheck-frontendcheck-go-formattingcheck-go-test-packagescheck-trailing-newlinecheck-trailing-whitespacedeploy-to-flydocker-imagee2e-testsgo-app-startergo-app-starter-devgo-testsjs-testslint-sqlscript-testsx86_64-linux