The org main-branch ruleset requires the status context `ci / ci`. A job
defined directly in a workflow emits only its job name, so this repo's CI
published `ci` and could never satisfy that rule. The two-part context comes
from a reusable-workflow call, named `<caller job> / <called job>`.
Move the checks into a local reusable and leave ci.yaml as a thin caller, which
is also the structural convention the org reusables follow. No org reusable
fits a bash and workflow tooling repo, so the reusable lives here.