Protect the jellyfin-config PVC (library metadata, plugins, config XML)
with daily restic backups to the new Ceph RGW config-backup bucket.
- Add a k8up.io Schedule: daily backup (02:00), weekly prune (Sun 03:00,
keep 14 daily/8 weekly/12 monthly) and weekly check (Sun 04:00)
- Source S3 creds from the cephrgw BucketAccess Secret and the restic
repo password from Vault via a VaultStaticSecret (kv path
kubernetes/namespace/jellyfin/default/k8up-restic)
- Add the namespace VaultAuth (default role/SA) VSO needs to sync it
- Mount the reflected vault-ca-cert into the restic pods so restic trusts
the internal unkin.net CA on s3.ceph.unkin.net
- Wire the new files into the jellyfin kustomization