OK I figured out how to get the group from authentik to map to the ClusterRole via the ClusterRoleBinding. I had to add - "oidc-groups-prefix=oidc:"
to the config.yaml in the k3s folder and access was granted! Thanks for the tutorials, will hit the dashboard up next to see this in action.