Regarding the missing cert file, is due to the env TMPDIR. Cert is expected to in /tmp/k8s-webhook-server/serving-certs/tls.crt. You can set the TMPDIR to /tmp.