controllers:
- watch for cluster.yaml updates & reflect addons annotations from cluster.yaml to argocd cluster yaml secrets
- watch argocd repo certs and check for expire, re-adding automatically
- tanzu watch for service associated with cluster to appear & annotate with fqdn automatically (in order to add dns entry for each cluster kubeapi)
- watch for certificate authority expiration and update ‘ca-bundle’ stored in vault