CoreDNS is Talos-bootstrapped and previously untracked except for its ConfigMap. Pull the full live spec into one file as the single source of truth, add topologySpreadConstraints so the 2 replicas don't land on the same node. ScheduleAnyway (not DoNotSchedule) to avoid blocking scheduling if a node is briefly unavailable.