This is really great - but this deploys a sidecar container per pod - how does it handle the case of multiple pods? does the argo tunnel load balance them or?

What’s the fix for ignoring cert errors, specifically a cert that does not contain any IP SANS?

"Unable to reach the origin service. The service may be down or it may not be responding to traffic from cloudflared: x509: cannot validate certificate for because it doesn't contain any IP SANs","time":"2022-05-11T23:22:53Z","message

Passing the --no-tls-verify flag on the command-line or adding the below into your configuration.

  - hostname: foo
    service: bar
      noTLSVerify: true

