The puppet-initial firstrun bootstrap hardcoded the legacy Consul CA
endpoint puppetca.query.consul:8140. That VM-era CA is being replaced by
the in-cluster puppetserver CA service.
- Default the CA host to puppetca.k8s.syd1.au.unkin.net (still :8140,
same /puppet-ca/v1/certificate/ca API; verified serving HTTP 200).
- Read PUPPETCA_HOST / PUPPETCA_PORT from the environment so a host can
be pointed at a different CA without rebuilding the RPM.
- Wire the env through systemd via EnvironmentFile=-/etc/sysconfig/puppet-initial
and ship a commented %config(noreplace) example at that path, so a
kickstart %post can override per-host.
- Document the override (incl. a kickstart %post example) in a new README.
- Bump el8/el9 build version 1.0.3 -> 1.0.4 so a new RPM is published.
Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv