Documenting stuff is really great, because you figure out that a lot of people seem to be doing it wrong.
Or can anybody tell me a valid use case for having an #etcd certificate have IP/DNS SANs of *all* cluster members? Assuming that they're all distinct and do not share load-balanced addresses between them?
From my reading, neither the `server` certificate nor the `peer certificate` need to be aware of the other cluster nodes and are completely node-focused.