Homelab
Private Tier HTTPS
Real HTTPS for Private Services: a Wildcard on a Private IP and One Default Certificate
Overview
The private tier gives every internal service a publicly trusted certificate and a hostname that resolves from anywhere but routes only from inside. It reuses the certificate foundation: one wildcard, issued by the DNS-01 issuer built there, served by ingress-nginx as its default certificate. A public DNS record answers that wildcard's names with a private IP. After this, publishing a private service is one Ingress with a hostname: no cert configuration, no browser warnings, and no service names in the public certificate logs.
Having trouble? See v2.2.0 for what your setup should look like after completing this article.
This article isn't ready yet
Check back soon for the full article.