The ops:drift three-way outcome is the right shape, treating "couldn't check" as its own state instead of folding it into "fine" is the same discipline that would've caught both failures here. One thing I'd want to know: is env-preflight wired into the deploy path itself so it runs and fails loud on every docker compose up -d, or is it a command someone has to remember to run afterward? The entire failure mode in both cases was silence, nothing complained, and if the preflight check is a manual step you've just moved the same trust-the-silence problem up one level, now you're trusting that someone ran preflight instead of trusting the deploy. The fix that actually closes the loop is making "recreated the container" and "ran preflight" the same event, not two things a human has to remember to chain.