Migrate VM puppet agents off the legacy VM puppetmasters and onto the new
puppet-on-kubernetes servers, per-wave via hiera and reversible without
re-enrolment. Changing server/ca_server alone is insufficient: the agent's
ssldir holds a cert signed by the OLD CA that the new CA neither trusts nor
recognises. This switches migrated nodes to a FRESH ssldir so the agent
generates a new CSR (autosigned on the k8s CA) while the old creds stay on
disk for rollback.
- Add profiles::puppet::migrate: opt-in (hiera_include) toggle that owns the
fresh ssldir directory and documents per-node/per-role/common wiring plus
rollback in its class header.
- Extend profiles::puppet::client with optional $ssldir and $report_server
params (default undef); the ERB template omits both lines when unset, so
unmigrated nodes render a byte-identical puppet.conf.
- puppet.conf stays owned solely by client.pp's template; migrate.pp adds no
competing File resource.