Repository navigation
Adds WithFileReader (#28), a ReloaderOption for NewCertificateReloader, ServerTLSConfig and ClientTLSConfig: the reloader reads the certificate and key through the caller's reader at startup and on every reload, so a service that validates its projected files beyond "parses as a key pair" (permission bits, a size bound, the path's shape) keeps applying that check to every rotated pair. A pair the reader rejects keeps the last good pair serving. The default stays os.ReadFile; existing callers are unchanged.