Certificate lifecycle: every cert in the homelab, from Let's Encrypt to the kubelet
Where every certificate in the homelab comes from and how it renews — cert-manager with the all-inkl DNS-01 webhook feeding Envoy Gateway listeners, kubelet-serving-cert-approver closing the node-cert gap, and Talos' own internal PKI underneath it all.