Self-signed certificate authority for a homelab in 30 lines of openssl: the trust-store install per-OS
For internet-facing domains, Let’s Encrypt is the right answer. But the moment you have a homelab service running on a .local domain, on a private subnet, or behind Tailscale — Let’s Encrypt either doesn’t work (HTTP-01 needs public reachability) or …