You open the console for the first time and the browser throws a certificate warning. Broken install? No — you are watching a CA bootstrap its own trust.
At first boot goca stands up its own hierarchy before anything else: it creates goca-infra-root → ica-infra and the goca-service-tls template, then issues every listener a real certificate and hot-swaps it in — usually within a second of the database being up. Until that first swap, the listeners serve an ephemeral self-signed bootstrap certificate, and your browser will warn.
The warning is expected in exactly two situations: this bootstrap moment, and a fault that the console's alert banner and Status → Components → Edge TLS will name. Anything else deserves investigation, not an "accept risk" click. From then on, certificates renew and hot-swap automatically — no cron job, no restart, no reverse proxy.
The warning itself persists until your machine trusts goca-infra-root — retiring it properly, trust-store quirks and all, is Your Own Certificate, the short section right after First Run. For the next few frames, clicking through on the loopback console is fine: you know exactly what you're accepting.
Now I can say when the browser warning is expected — and when it's a fault with a name.