* Controllers receive etcd TLS credentials * Controllers and workers receive a kubeconfig
* Avoid adding SSH authorized key for user "core" during the disk install, so that terraform apply cannot SSH until post-install