If you want good integrity controls, treating the CA bundles as secrets (e.g., storing them in k8s secrets or something like Vault) can help there. We don't actually care much about confidentiality controls, but any secret manager worth its salt is going to have integrity controls as well. This gives you easy updates and lets you reuse containers across environments while remaining defensive against attackers adding their own CA to the store.