3 CP nodes available — run one CNPG instance per node for proper HA.
2 instances loses quorum on single node failure.
memory-db stays at 2 (acceptable for that workload).
Fixes controlplane.tftpl's install.wipe:true (should be false, live CPs already run false) and syncs coredns Corefile back to what's actually deployed (drops an unrolled-out, stale Kong-era rewrite).