Replace the out-of-band cephrgw-credentials Secret with a VSO-managed one so
the operator's Ceph dashboard credentials come from Vault.
- Add apps/base/cephrgw-system/vaultauth.yaml: VaultAuth (k8s/au/syd1 mount,
role cephrgw-operator, SA cephrgw-operator, connection vso-system/default).
- Add apps/base/cephrgw-system/vaultstaticsecret.yaml: renders the KV path
service/cephrgw/dashboard-credentials into the cephrgw-credentials Secret
(keys copied verbatim, consumed by the Deployment via envFrom).
- Reference both from the base kustomization.
Requires the Vault role/policy from terraform-vault #95 and the KV values to
be seeded (see the operator's docs/ceph-setup.md).