For clearnet use Caddy as a reverse proxy on the VPS, with directives to whatever... your self signed certs mean nothing to any system including your own without a CA whitelisted on every device that uses it
Yeah caddy is the simplest option, works really nice.
reply