identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so
tls_client_ca pointing at the internal unkin.net root is the only trust anchor
Grafana offers generic_oauth and the handshake fails. Drop the setting and the
now-unused vault-ca-cert mount; the image's public roots cover it.