4434265cf6
The clouddns approach is dropped in favour of self-delegating the ACME challenge to our own BIND: a one-time CNAME sends _acme-challenge.unkin.net into acme.unkin.net (served by bind-external), and cert-manager solves DNS-01 via RFC2136+TSIG against it. No GCP service account or Vault KV secret needed. - Replace the dns01 clouddns solver in both ClusterIssuers with rfc2136 (nameserver 198.18.199.53:53, key certmanager, HMACSHA256, secret certmanager-tsig reflected into the cert-manager namespace). - Remove the now-unneeded VaultAuth, VaultStaticSecret and clouddns ServiceAccount. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT