fix(install): address CodeRabbit review round 2

- Workflow: use github.ref for the concurrency group so distinct PRs from the
  same source branch don't cancel each other
- Workflow: extract the generated DB password from the installer's 'Password:'
  output and verify the 'ospos' account can authenticate with DB_PASS
- Installer: set the MariaDB root password and FLUSH PRIVILEGES in one session,
  pass the root password via a private 0600 defaults file (no argv exposure),
  and scope the SQL account to the 'localhost' client host
- Docs: interactive mode requires a tty (download-then-run, not a pipe);
  clarify SSL_EMAIL needs a public hostname to enable Let's Encrypt
This commit is contained in:
Internal Server Error - Gitea: Git with a cup of tea
500 Internal Server Error

Gitea Version: 1.28.0+dev-477-g8b6ad49a5f