Server was crash-looping on TLS trust failures fetching Authentik's OIDC discovery document (private-CA cert not trusted by the container image). Drop the auth wiring for now to unblock the deployment; internal/auth and internal/api/interceptors packages are left intact for when auth comes back.