It would be useful to have an ability to designate where a corporate firewall's self-signed certificate could simply be specified rather than having to build a custom local image of each kind such that when present, any files contained therein would be fed into the pki infrastructure and "update-ca-trust" could be run before attempting to connect to sites outside of said firewall.
Perhaps a "-v $CERT_DIR:/etc/pki/ca-trust/source/anchors:z" option and if the directory is not empty, update the trust before doing any builds.