I wrote up what I found, how VM placement can drift during migrations and maintenance, and how Proxmox HA resource affinity rules can help keep redundant workloads on separate nodes.
The bigger lesson for me was that two copies of a service do not necessarily mean two separate failure domains.