Ask a CA vendor how their own admin console gets its TLS certificate. The honest answers are usually a self-signed certificate you're told to click through forever, or a reverse proxy someone else has to feed.
goca answers by being a CA. At first boot it stands up its own internal hierarchy — goca-infra-root → ica-infra — and issues every listener a real certificate, usually within a second of the database being up. From then on an in-process loop renews and hot-swaps those certificates on its own: no cron job, no restart, no reverse proxy.
You'll watch this happen in First Run, then put your own hierarchy behind the console in Your Own Certificate, right after it.