> When would you need to revoke an individual cert and why wouldn't that be better handled by just shutting down the VM or container instead?
You revoke a cert when it's somehow been compromised and something other than the VM/container that's supposed to has it gets a copy of it.