In a separate issue, should we decouple privkey management from cert handling? _Originally posted by @sed-i in https://github.com/canonical/observability-libs/pull/66#discussion_r1407053949_