I think that we do not need the ca-certificates package to be present for oathkeeper (does oathkeeper call kratos through https?).
BUT even if we do need the ca certificates bundle, we should use the ca-certficates slice (e.g. see canonical/kratos-rock#142).