The /healthz route was registered inside httpapi.Server.Routes() but
the root mux only attached that handler at /auth/ and /api/, so any
request to /healthz fell through to the static file server and got
404'd. Caddy's reverse-proxy and the deploy workflow's curl-based
health check both hit the public origin, so the in-container
healthcheck reported 'unhealthy' and CI never marked the deploy as
verified.
Mount /healthz on the root mux explicitly. Add a serve_test.go that
asserts the same routing topology so the regression cannot return
silently.