9616e0e2b3
rke2's `registries.yaml` already rewrites upstream image names to the artifactapi mirror, so manifests must carry canonical upstream names. Only in-house `artifactapi.k8s.syd1.au.unkin.net/docker-internal/...` images stay explicit. Changes: - Point the arrproxy migrate job at `docker.io/library/postgres:18-alpine`. - Point the arrproxy oauth2-proxy cert-combine init container at `docker.io/library/alpine:3`. - Point the arrstack ValkeyCluster at `docker.io/valkey/valkey:9.0.0`. Tags are unchanged. `kustomize build --enable-helm apps/overlays/au-syd1/arrstack` differs from main only in those three image strings. No extra proxied refs found in these files (the oauth2-proxy image itself is already canonical `quay.io/...`). Reviewed-on: #427 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>