* feat(deployment): guard servers from destroy and stage production talos reboots
Add prevent_destroy to the OVH control-plane instances, the bare-metal
workers, and the Talos machine secrets so a plan that would replace or
delete one fails instead of applying.
Add a talos apply_mode variable. Production applies with
staged_if_needing_reboot: a machine-config change that needs a reboot is
written to the node but stays inactive until an operator reboots it, one
node at a time. Staging keeps auto so the reboot path is exercised there
first. The provider has no try-style auto-revert mode, and the per-node
applies are unordered, so this is the only lever that stops a bad config
from rebooting every control plane at once.
Document both behaviours in the bootstrap guide.
Signed-off-by: Devin Buhl <devin@buhl.casa>
* chore(rootly): refresh provider lock hashes
Signed-off-by: Devin Buhl <devin@buhl.casa>
---------
Signed-off-by: Devin Buhl <devin@buhl.casa>