af1f77618d
The authorize step is a browser redirect, so the issuer must present a publicly-trusted cert; identity.k8s.syd1.au.unkin.net serves an internal-CA cert that no user's browser trusts. - Point OAUTH2_PROXY_OIDC_ISSUER_URL at identity.unkin.net - Drop the combine-certs initContainer, its volumes/mounts and PROVIDER_CA_FILES: the pod's only other upstream is plain-HTTP in-cluster