Ceph dashboard SSO is SAML 2.0 (no native OIDC), so onboard it via an Authentik
SAML provider + application. Also resolve SAML authorization/invalidation flows
by slug and the signing keypair by name (mirrors the oauth2 handling), since the
SAML path had not been exercised before.
- config/providers_saml/ceph.yaml: SP entity id/ACS derived from the dashboard
base URL (audience .../auth/saml2/metadata, acs .../auth/saml2, HTTP-POST),
signed with the built-in self-signed keypair.
Ceph side (separate, Puppet): ceph dashboard sso setup saml2
https://dashboard.ceph.unkin.net <authentik-idp-metadata-url>
Validated with `terragrunt plan`: 2 to add (provider + application).