The implementation of certificate trust environment and argument configs is currently implemented only in the DcpExecutor internals. We should update the implementation to rely on standard environment and argument annotations.
The main issue we'd need to resolve is whether we can model an all-or-nothing approach to this configuration to avoid conflicts with manual user config.