I have generated my Self-Signed certificate using cert-manager. The secret containing the data has the key ca.crt and not cawhich is the standard I think. There should be a fix for setting the key using a CLI-flag. The image is used by capsule-proxy.