Wildcard Certs on Internal-Only Hostnames: Why DNS-01 Is the Only Real Option
How to get valid, trusted HTTPS certificates for LAN-only homelab services using the ACME DNS-01 challenge, without exposing anything to the internet.
$ ls ./dns
How to get valid, trusted HTTPS certificates for LAN-only homelab services using the ACME DNS-01 challenge, without exposing anything to the internet.
How to make service.example.com resolve to a different address inside your LAN than it does on the public internet, and why skipping this causes broken NAT hairpinning and cert mismatches.
Why Pi-hole or AdGuard Home fails to bind port 53 on a fresh Debian/Ubuntu host, and the difference between disabling the stub listener and actually freeing the port.
A dead resolver from a Tailscale experiment months ago kept leaking into brand-new containers, breaking DNS resolution in ways that look like an app bug. Here's how it propagates and the two ways to catch it.