What broke
Site P4 had three env files (local, staging, production). The staging file held the old API key for a third-party integration. When CI Provider C re-ran staging tests against production-shaped data, it used the staging key, and the integration started returning 503 on every checkout flow.
How it was fixed
Consolidated to a single source of truth for env config, with explicit "production-only" tags that require review on change. CI Provider C now refuses to deploy if any production-only env value differs from the staging override.
Monitoring rule that would have caught it
Run a synthetic ping against the third-party integration with the production key from CI on every deploy. Treat env drift as a deployment pre-condition, not a runtime concern — catching it at deploy time costs minutes; catching it in production costs hours.