Consume the two-tier Authentik RBAC (terraform-authentik): request the
hierarchical `ak_groups` scope/claim and map the `akP-argocd-admin` permission
group to role:admin (replacing the flat `argocd-admins`). Members of
akR-global-admin inherit akP-argocd-admin, so they get ArgoCD admin.
- argocd-cm: add `ak_groups` to requestedScopes + requestedIDTokenClaims
- argocd-rbac-cm: scopes [ak_groups]; policy.csv g, akP-argocd-admin, role:admin