
Fixes #27684. For now, I'm simply poking a hole to grab the system /etc/ssl/certs. If we decide we want something less dependent on the node filesystem, we will need to decide how we pick a "distro" more sophisticated than busybox for federation components running on k8s. I'll open a followup issue to discuss this.