Three fixes out of a comprehensive code analysis pass:
Workers Actually Retry Now
The worker's reserve loop buried any job that had ever been released or timed out -- meaning every retry path in the system was dead on arrival. A package-price job released for a transient failure, a month scrape released for a rate-limit hiccup, a job orphaned by a deploy's worker SIGKILL: all of them got buried the moment they came back, instead of retrying. Jobs now get a real retry budget (3 combined releases + timeouts) before burial.
Scheduler Dead-Man's Switch
The scheduler can detect and alert on almost anything -- except its own death. Cron misconfiguration or a bootstrap fatal would just make everything quietly stop. It now pings an external dead-man's-switch URL at the end of every successful tick, so an outside monitor screams when the pings stop. The /health endpoint also gained a deep mode reporting scheduler liveness, worker count, and price-insert freshness for external uptime pollers.
Deploy Hardening
The remote deploy script now uses pipefail, so a failed composer install aborts the deploy instead of shipping a partial vendor tree because the pipe's tail exit code masked it.