Not at all the point of this question, but I showed this title to some friends and had them guess what the acronyms meant because. Its always fun to say phrases that 99% of the population can't even begin to understand.
I am interested in this as well! Two thoughts would be running systemd-resolved or configured coredns to point to an external TLS DNS server in an container and change NetworkManager configuration to point to that service.
I think you use ignition to change system configs like NetworkManager but I don't really know! Just digging into microos myself.