Add vic.rubenhensen.nl to tunneledHosts so the edge box does SNI
passthrough on :443 and the :80 ACME/redirect vhost for it, matching
the DNS record. Without this, vic falls through to Stalwart on :8443
and cert-manager's HTTP-01 challenge can't be reached.
Single-pod sqlite install (simplest path for a home git host). HTTPS-only,
no SSH listener for now. Wired into the Hetzner tunnel like the other
rubenhensen.nl services.
First visitor to git.rubenhensen.nl can register; Gitea auto-promotes the
first user to admin.
Point rss to the Hetzner box and reverse-proxy/SNI-passthrough back to
the home cluster so cert-manager keeps owning the certificate. Move
stalwart's HTTPS listener to 127.0.0.1:8443 so nginx can take :443 and
dispatch by SNI.
- Add LDAP directory backend in Stalwart pointing to ldap.rubenhensen.nl
- Expose Authentik LDAP outpost externally via LoadBalancer service
- Add ldap.rubenhensen.nl DNS record