Reaching mw-api-int.discovery.wmnet from envoy service proxy fails, we are missing the correct SANs for all mw-on-k8s deployments.
[x] Add `"mw-api-ext.discovery.wmnet", "mw-api-ext-ro.discovery.wmnet", "mw-api-ext.svc.eqiad.wmnet", "mw-api-ext.svc.codfw.wmnet", "mw-api-int.discovery.wmnet","mw-api-int-ro.discovery.wmnet", "mw-api-int.svc.eqiad.wmnet", "mw-api-int.svc.codfw.wmnet"` to `appservers-rw.discovery.wmnet` stanza in mediawiki.certs.yaml
[x] Add `"mw-api-ext.discovery.wmnet", "mw-api-ext-ro.discovery.wmnet", "mw-api-ext.svc.eqiad.wmnet", "mw-api-ext.svc.codfw.wmnet", "mw-api-int.discovery.wmnet","mw-api-int-ro.discovery.wmnet", "mw-api-int.svc.eqiad.wmnet", "mw-api-int.svc.codfw.wmnet"` to `api-rw.discovery.wmnet` stanza in mediawiki.certs.yaml
[x] `puppet cert clean appservers-rw.discovery.wmnet`
[x] `puppet cert clean api-rw.discovery.wmnet`
[x] `rm /srv/private/modules/secret/secrets/certificates/appservers-rw.discovery.wmnet/{appservers-rw.discovery.wmnet.crt.pem,appservers-rw.discovery.wmnet.csr.pem}`
[x] `rm /srv/private/modules/secret/secrets/certificates/api-rw.discovery.wmnet/{api-rw.discovery.wmnet.crt.pem,api-rw.discovery.wmnet.csr.pem}`
[x] `cergen -c 'appservers-rw.*' --generate --base-path=/srv/private/modules/secret/secrets/certificates /srv/private/modules/secret/secrets/certificates/certificate.manifests.d`
[x] `cergen -c 'api-rw.*' --generate --base-path=/srv/private/modules/secret/secrets/certificates /srv/private/modules/secret/secrets/certificates/certificate.manifests.d`
[x] Commit the changes to the private repo
[x] Copy `/srv/private/modules/secret/secrets/certificates/appservers-rw.discovery.wmnet/appservers-rw.discovery.wmnet.crt.pem` to puppet `./modules/profile/files/ssl/appservers.svc.{eqiad,codfw}.wmnet.crt`
[x] Copy `/srv/private/modules/secret/secrets/certificates/api-rw.discovery.wmnet/api-rw.discovery.wmnet.crt.pem` to puppet `./modules/profile/files/ssl/api.svc.{eqiad,codfw}.wmnet.crt`
[x] Commit public puppet changes