380eb63277
deploy/fleetd.service started clean on fleet01 but broke the daemon in three ways nothing logs: ProtectSystem/ProtectHome/ProtectKernelTunables/ProtectControlGroups each put the unit in its own mount namespace, which blinds fleetd's lsof-based caller lookup and falls every caller back to ANONYMOUS; PrivateTmp=true silently no-ops the credential scrub the member pane depends on; and running java directly from ExecStart skips the login shell that sources the daemon's secrets, so it boots with empty credentials. Replace the unit with the version verified working on fleet01 for a day, and add the deploy/herdr.service companion unit it was already depending on via After=/Wants= but which did not exist in the repo. Add deploy/herdr-inner.sh as the login-shell template herdr.service's ExecStart wraps in a pty. Add SystemdUnitSafetyTest (fleetd/src/test/java/dev/ltms/fleet/deploy) to read both unit files from disk and fail if a forbidden mount-namespacing directive is active, PrivateTmp is true, or fleetd.service's ExecStart does not go through a login shell -- the only guard possible for a unit file with no compile step.