mediamark should consume ephemeral virtual sonarr/radarr keys from the
arrstack engine instead of copies of the static app API keys.
- add arrstack role "mediamark" scoped to sonarr + radarr (60s ttl, 24h
max_ttl, mirroring the existing per-app roles)
- add k8s/au/syd1 auth role "mediamark" bound to serviceaccount default in
namespace mediamark
- grant read on arrstack/creds/mediamark to that role only