In the light of T329556: K8s etcd on bullseye show TLS errors in logs we should configure the wikikube-staging etcd clusters to use PKI instead of cergen certs
https://gerrit.wikimedia.org/r/c/operations/puppet/+/889082/
- staging codfw
- staging eqiad
- clean up cergen certs in private puppet