1ea0dc920c
identity.unkin.net is now the canonical Authentik host. Gitea reaches it for OIDC discovery/JWKS over TLS served by the internal unkin.net CA, which the rootless image doesn't trust. - Flip the authentik login source autoDiscoverUrl to identity.unkin.net. - Mount the reflected vault-ca-cert and add it to Gitea's Go trust pool via SSL_CERT_DIR (additive; public roots stay intact). Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv Signed-off-by: Ben Vincent <ben@unkin.net>