The "rotate NATS Certificate" job needs to be run at least once a year on control-tower, otherwise the system breaks and is very difficult to recover.
See https://github.com/EngineerBetter/control-tower/blob/master/docs/troubleshooting.md#nats-certificate-is-expired and #334
A job to do this automatically on a set schedule ought to be included out of the box in the "self update" section.
If there is some reason this can't be done automatically, the documentation ought to explain how to set this up manually, so the install doesn't fail yearly.