···48484949 # ── ACME wildcard cert for tailnet vhosts ─────────────────────────────────
5050 # Uses Cloudflare DNS-01 so no port needs to be opened. Covers all
5151- # *.ewancroft.uk tailnet services (Nextcloud, Immich, Jellyfin, Cockpit).
5151+ # *.ewancroft.uk tailnet services (Nextcloud, Immich, Jellyfin, Grafana).
5252 #
5353 # Prerequisite: create and sops-encrypt secrets/cloudflare-acme.env
5454 # containing the raw token value only (no KEY= prefix, no trailing newline).