One other thing I did was use OpenBao for managing FDB cluster configuration.
That originally started with TLS certificate issuance only, but I needed to manage JWT signer keys as well, and then I put some other configuration in as well that was not completely security related since I didn’t want to deploy a 2nd tool.
Planning to set up an SSH CA soon.