Wildcard Certs on Internal-Only Hostnames: Why DNS-01 Is the Only Real Option
How to get valid, trusted HTTPS certificates for LAN-only homelab services using the ACME DNS-01 challenge, without exposing anything to the internet.
$ ls ./reverse-proxy
How to get valid, trusted HTTPS certificates for LAN-only homelab services using the ACME DNS-01 challenge, without exposing anything to the internet.
How to make service.example.com resolve to a different address inside your LAN than it does on the public internet, and why skipping this causes broken NAT hairpinning and cert mismatches.