82ea72383c
## Summary `workload_auth_gate_total` records how each worker action authorizes: scoped by a verified environment header, grandfathered by the created-at gate, or suppressed by it. It was registered on the Prometheus registry served at `/metrics`, which is per-process. With `ENABLE_CLUSTER=1` every Node worker keeps its own registry, so a scrape returns whichever process happened to answer and the counter reads as a fraction of real traffic. This moves the counter onto the OpenTelemetry meter the webapp already uses for its other engine metrics. Each process exports under its own `service.instance.id`, so summing across them gives the true total no matter how many workers a deployment runs. ## Attributes The counter now carries `env_type` and `run_age_bucket` alongside `outcome` and `action`. `run_age_bucket` is the coarse age of the run behind an untokened worker action (`lt_1h`, `1h_1d`, `1d_7d`, `7d_30d`, `gt_30d`). It exists so an operator can size `WORKLOAD_TOKEN_CUTOFF` before committing to it: set the cutoff far in the future and every run is grandfathered, so the age distribution of untokened traffic is visible without anything being rejected. Both attributes come off the run row the gate already reads, so there is no extra query.