* feat(terraform): ship dev content CD through Terraform (SH-300)
GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.
* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
* ci(terraform-isolation): re-evaluate the gate on label changes
* test(terraform-isolation): lock the ci.yaml label-event contract
* fix(terraform-isolation): do not treat terraform markdown as a mixed change
* fix(ci): do not skip Frontend checks on isolation label events
* ci(terraform-isolation): run label retriggers in a dedicated workflow
* fix: apply eslint formatting
* fix: apply additional missed eslint formatting
Port the reviewed dev root and environment-owned/inventory modules from
111eb556 with the 13 pinned dev identifiers. adoption_complete is pinned
to false in code; the root has no variables so a workspace variable
cannot change what applies. The tf-poc root, staging root, and tf-poc
map entries are dropped; staging constants stay only for the checker's
cross-environment negative tests.