- tests/bluesky-pds/recipe_meta.py: HEALTH_PATH=/xrpc/_health, 600s timeouts. - tests/bluesky-pds/install_steps.sh: recipe needs pds_plc_rotation_key (32-byte secp256k1 hex, marked generate=false). Hook generates via cc-ci-run python (secrets.token_bytes(32); random 32-byte value is almost-always a valid secp256k1 private key, ~2^-128 fail rate). Inserted via 'abra app secret insert' under TTY-wrap. Per-run class-B; destroyed at teardown. - tests/bluesky-pds/PARITY.md: no health_check.py in the recipe-maintainer corpus -> Phase-2 health_check aligned with parity convention. goat_account.py parity deferred (needs goat CLI in container; operational complexity). - 3 functional tests: - test_health_check.py: GET /xrpc/_health -> 200, {version: ...}. - test_describe_server.py: GET /xrpc/com.atproto.server.describeServer -> 200, JSON with atproto config keys (availableUserDomains/inviteCodeRequired/links/did). - test_session_auth.py: GET /xrpc/com.atproto.server.getSession (no auth) -> 401 + JSON XRPC error envelope. (Replaced test_well_known_did — /.well-known/atproto-did isn't auto-published by the recipe.) Cold-verifiable: ssh cc-ci 'RECIPE=bluesky-pds STAGES=install,custom cc-ci-run runner/run_recipe_ci.py' install + 3 custom tests all PASS, deploy-count=1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>