This is a really useful distinction between checking whether PostgreSQL is alive and checking whether a node is actually suitable for a specific kind of traffic.
The point about /health being a poor choice for write routing stood out to me. A node can be perfectly healthy from PostgreSQL's perspective while still being the wrong target for writes. I also like the idea of testing the whole path through HAProxy rather than trusting the Patroni endpoint alone.
The pg_is_in_recovery() check is a nice final verification because it tests what the application actually reaches, not just what the health check reports. That kind of end-to-end validation seems especially valuable during failover.