repo deploy-key add on a key that is already registered as a user key does not fail and
does not add a second registration. It converts the existing one, and removing the deploy
key then deletes the key outright.
What happened on a live instance: the CI runner's key was registered as a user key with
full scope. Registering that same public key as a repository deploy key re-scoped it,
and the runner stopped:
runner: claiming build: exit status 4 (this key's scope (deploy:26:rw) does not allow control commands
Removing the deploy key to undo it did not restore the user key — it unregistered the key entirely:
runner: claiming build: exit status 4 (this key is not registered here. Create an account with:
ssh <host> register --username <name> --email <address>
Recovering needed keys add --scope full from a second machine that still had a working
key. An instance whose only registered key was the one converted this way would have no
way back in over SSH.
Two things would each have prevented it: refusing deploy-key add for a key that is
already registered, naming the conflict; or scoping the two registrations independently so
that removing a deploy key restores nothing but the deploy grant.