Served by nginx, fronted by Traefik, with a Let's Encrypt certificate obtained via the HTTP-01 challenge.
| Host | hello.sonny.xiat.net |
|---|---|
| Backend | nginx:alpine — publishes no host ports |
| Proxy | Traefik v3.7 — TLS terminated here |
| Certificate | Let's Encrypt, persisted in ./data/acme.json |
If this loaded over HTTPS without a browser warning, the whole chain worked: DNS → Traefik → ACME HTTP-01 → nginx.