Addresses errcheck, gosec, revive, staticcheck, and unused findings
across the codebase (unchecked error returns, unsafe file inclusion
warnings on operator/test-controlled paths, missing package comments,
unused parameters, deprecated API usage). Also fixes two suppression
comments that were silently no-ops due to wrong syntax (#nosec needs
a leading '#', nolint reasons need '//' not '--').
With the backlog clear, drop continue-on-error from the CI lint job
per the plan left in b4b4806.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- internal/logging now wraps log/slog; logging.format json/text finally
works (json is the documented default). Same exported API.
- New internal/metrics: /metrics on the configured metrics port with
notification gauges by status/type, queue depth, and HTTP request
count/duration labeled by mux route pattern; sampled from service
stats so the service layer stays metrics-agnostic.
- Standard grpc.health.v1 health service registered (k8s gRPC probes);
gRPC MaxRecvMsgSize bounded to match the REST 1 MB body limit.
- Dedicated health listener on health_check.port serving /health and
/readyz (probes now work in grpc-only mode); metrics, health, and
REST servers all shut down gracefully.
- main wires retry backoff, CORS, readiness checks, and TLS from config.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>