- Remove OIDC config from helm-values - Remove ExternalSecret (not needed) - Add Authelia middleware to ingress - Headlamp uses ServiceAccount for K8s API access
- Add OIDC configuration (clientID, issuerURL, scopes) - Add ExternalSecret for OIDC client secret from Vault - Remove Authelia middleware (using direct OIDC auth)