

is there an easier way to do self-signed certs besides spinning up your own certificate authority?
Letsencrypt works fine, just use a “real” domain and DNS challenge.
Your service will need to be on the “real” domain, but it won’t need to be accessible externally and you won’t need a public DNS entry for it (of course your VPS will still need to be able to resolve the backend’s name).


Isn’t that how Amazon prime works?