Gardener v1.87+ shoot API server certificate rotation: transient x509 failures when control plane restarts during renewal
On Gardener v1.87+ shoots, certificate rotation via cert-manager updates the serving certificate secret, and the kube-apiserver is expected to pick it up through its TLS file watcher (Kubernetes >= v1.22) without a restart. The new CA bundle is then propagated to clients through the shoot's status credentials. My concern is the ordering gap: if the kube-a