Add DynamicCALoader and DynamicTLSTransport for hot-reloadable CA
certificates without requiring application restart.
- DynamicCALoader: watches CA files via fsnotify and reloads on change,
supports Kubernetes ConfigMap/Secret symlink replacement pattern
- DynamicTLSTransport: wraps http.Transport with dynamic CA verification
using VerifyPeerCertificate callback
- Add atomic transport proxy to http.go for runtime transport swapping
Signed-off-by: Niki Dokovski <nickytd@gmail.com>