> Questions come up: do you block a request if you fail to download the latest CRL? How often do you refresh it?
In the before times we left settings like this up to competent system administrators to decide based on risk and not hardcoded by a handful of people at Google.
> competent system administrators
Sorry, we don't hire those anymore.
Best I can do is a YAML monkey who knows how to glue cloud services together..