Used to secure connections between the kube-apiserver and aggregated API Servers.
TODO need to work out who and what.
Used by the OpenShift platform to recognize the proxy. Other usages are side-effects which work by accident and not by principled design.
Used to secure inter-service communication on the local cluster.
Used to secure etcd internal communication and by apiservers to access etcd.
Used to access etcd metrics using mTLS.
Used by the kube-apiserver to recognize clients using mTLS.
Used by kube-apiserver clients to recognize the kube-apiserver.