Register the k8s Gitea forge as an Authentik OIDC app so it can use SSO at
cutover. Redirect URIs cover both the temporary git2 validation host and the
final git.unkin.net host so login works across the migration.
- add config/providers_oauth2/gitea.yaml (confidential OAuth2 provider + app,
client_secret read from kv/kubernetes/namespace/gitea/default/oauth-credentials)
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv