feat: gRPC health check monitors master
Adds a fifth monitor type that calls grpc.health.v1.Health/Check and reports the serving status it answers with. The probing tier and the TypeScript tier move together, per apps/checker/AGENTS.md: the Go checker, the private-location agent, the proto contracts and the product surface are all in this change. Notable decisions: - Health protocol only. No reflection, no arbitrary unary calls. - Two additive monitor columns, grpc_service and grpc_tls, rather than encoding the configuration into the URI — a URI parser would have had to exist in Go twice and TypeScript four times. - Only transport failures are retried. A server that answers NOT_SERVING, SERVICE_UNKNOWN or UNIMPLEMENTED is recorded once, the way an HTTP assertion failure already is, so alerts are not delayed by the backoff window. - GRPCResult carries an explicit Completed flag. It cannot be derived from the error flag, because NOT_SERVING is a failed check that completed perfectly well. Completion drives retry, OTel branching, what latency and timing hold, and the latency-quantile filter. - Timings reuse HTTP's ten-field shape verbatim, so calculateTiming and the dashboard waterfall work with no new code. - UNIMPLEMENTED gets its own message: the server is reachable, it just never registered a health service, and reading that as "down" sends people hunting the wrong problem. - TLS failures return a fixed string. The raw error quotes the peer's certificate subject and chain, which must not reach the caller. The three defects the ICMP pipes shipped with are fixed in the gRPC copies rather than inherited: no SELECT * in a materialization, the regions parameter is actually used, and the 30d/90d latency endpoints honour the forwarded window. Latency quantiles additionally exclude checks whose RPC never completed, so a refused connection no longer drags the median toward zero. While adding the fifth ingest validator, the monitor-id, latency and timestamp checks the four existing ones duplicated were extracted into one helper. mapMonitors gained a logging default so an unsupported job type can no longer vanish without a row, a log or an error. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YDMfxo4TidoFQt93wcnsYm