Add Authentik blueprint for Zot with OAuth2 provider, application,
artifact-workloads group, and zot-ci service account. Wire the client
secret through ExternalSecret and worker deployment env var. Add Ansible
pre_task to fetch the OIDC secret from 1Password and a template task
to deploy oidc-credentials.json to indri.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>