At the moment PKI and haproxy do listen for the same notify, which results in haproxy trying to generate certs in inappropriate places. This patch starts leveraging `pki_handler_cert_installed` variable that enables us to trigger haproxy certificate assemble only when required and expected. Co-Authored-By: Damian Dąbrowski <damian@dabrowski.cloud> Depends-On: https://review.opendev.org/c/openstack/ansible-role-pki/+/875757 Change-Id: I66f648e5c3104f71d6601a493b09f8cdcc3332fc