Generate default CA via ssh/config/ca, split composite KUBECTL for role writes, read pubkey from config/ca, allow warden key_id in roles, prefer production kubeconfig.
Declarative roles, warden-sign policy, apply/verify scripts, and Makefile targets openbao-configure-ssh and openbao-verify-ssh. Document operator flow in docs/openbao.md for NET-WP-0020 T5 / WP-0008 T2.