Currently Tornjak expects static ca's that do not automatically rotate. Now that Tornjak is part of helm charts, and various components can easily gain access to SPIRE-issued certificates, would be ideal if Tornjak took advantage of this like the SPIFFE OIDC provider.