refactor(orbit): rename orbit_local config keys to orbit_cli
Description
The Orbit package and asset names already use orbit-cli. The config keys were the last orbit_local name. This change renames them to orbit_cli_* and GLAB_ORBIT_CLI_*. The new keys match the existing duo_cli keys.
This change keeps no back-compat shims. Orbit is beta, so it removes the old names instead of adding aliases. The build generates the docs in docs/source/ again from the schema.
This change is related to gitlab-org/orbit/knowledge-graph!2577 (merged), which removes the orbit-local release artifacts.
Risk
This change breaks setups that use the old names, but Orbit is beta. The auto-managed keys re-derive on the next run. Users set orbit_cli_auto_run, orbit_cli_auto_download, and any GLAB_ORBIT_CLI_BINARY_PATH override again. This costs less than a compatibility layer.
How has this been tested?
I ran go build, go vet, gofmt, and make gen-docs. The package tests pass for internal/config, internal/binarymgr, and internal/commands/orbit. Two unrelated credential tests fail only on this machine, because the local keyring gives them a real token. They pass in CI.