8e508c231e
identity.unkin.net moved from the internal unkin.net CA to the LetsEncrypt *.unkin.net wildcard, so pinning the internal root made argocd-server reject the OIDC discovery handshake (x509: certificate signed by unknown authority). The stock image trust store already carries the public roots.