>>106488934
At first I didn't understand this but after taking the time to set it up it made sense, this solution is genius. I assumed I would have to open services to the world in order to be able to have an SSL cert for them, but a combination of this and this other anon's approach here >>106475503 with a wildcard *.mydomain.com cert with DNS-01 authentication made it all work perfectly without the need for any extra shit like a CA or secondary domains. At home I just re-route all mydomain.com request to my home server's IP via Pihole with local static DNS rules, including subdomains that are not reachable through the internet, and out of the house I'm only able to reach exactly what I chose to expose. Thanks a lot frens, I learned a lot this past week.