My point was not to use http only as a finished solution, but to let the admin front the http-only service with their TLS termination solution of choice.
My point was not to use http only as a finished solution, but to let the admin front the http-only service with their TLS termination solution of choice.
I self-host Immich with Caddy as TLS terminator, and it's far from obvious.
They all run on a small N150 PC in my closet, the same PC serves as my internet router. Both Immich and Caddy run in podman-compose, and there are firewall rules that allow incoming traffic to Caddy and outgoing traffic from Caddy to update certificates. There's also a tricky setup of Systemd dependencies that make sure podman networking and firewall rules play nicely together and with other system config, like the bridge for the 2.4Gz range internal Wi-Fi and for external 5Gz Wi-Fi 6 card.
If not for the LLM help, I would have spent many days figuring out all the rough edges of this setup.
Which is exactly the point OP is making. Hobbying webhosting is hard nowadays.