Wire up OIDC authentication via jellyfin-plugin-sso so all Authentik
users can access Jellyfin, with admins group mapped to Jellyfin admin.
- Authentik blueprint: OAuth2 provider + application (no policy binding)
- ExternalSecret + worker env var for client secret
- Ansible: fetch client secret, install SSO-Auth plugin, deploy config
- Local login left enabled (no branding override)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>