Reduce cloud-provider egress for scale-out perf testing: every node image pull
is rewritten to a registry:2 pull-through cache running on the bastion
host. First pull of a unique image still goes upstream (bastion → provider);
all subsequent pulls from any node are served from the bastion at L2 speed.
Tested on OpenShift 4.20 / vSphere IPI, CRI-O 1.36.5, ~50-80 churning
autoscaled workers pulling quay-proxy.ci.openshift.org CI images.