363ef0ba66
Add `nodectl bootstrap-token -node=<uuid>` subcommand that issues a one-time Redis-backed enrollment token for a node UUID. Operators use this to re-enroll a node after cert expiry or state loss without having to re-provision the machine. - wires mtls.BootstrapTokenManager via REDIS_ADDR / REDIS_PASSWORD env vars - prints 64-char hex token to stdout (same format as cloud-init path) - updates usage() and package-level doc comment to document the new subcommand - adds cmd/nodectl/bootstrap_token_test.go with 5 unit tests (miniredis, no external deps): token format, one-time guarantee, missing-flag error, unreachable Redis error, unknown subcommand regression guard Compilation: `go build ./...` clean. Tests: `go test ./...` all pass (31 packages). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>