identity.unkin.net moved from the internal unkin.net CA to the LetsEncrypt
*.unkin.net wildcard, so pinning the internal root made argocd-server reject
the OIDC discovery handshake (x509: certificate signed by unknown authority).
The stock image trust store already carries the public roots.