a3fa110feb
This PR attempts to: * Generally clean up the bootstrapping token doc. * Separate the authentication and signing features. Help users that only want to enable the authenticator without the signer. * Adds a warning about ConfigMap signing being susceptible to MITM if the same token is reused.