logoalt Hacker News

silverwindlast Monday at 6:31 PM1 replyview on HN

Not a problem if you have the cert on a shared load balancer, not on the services directly.


Replies

0127last Monday at 7:35 PM

This is what we do for development containers/hosts - put them behind *.dev.example.com, allows us to hide most testing instances using a shared load balancer. And with a single wildcard CNAME, No info is leaked in CT logs or DNS. Said LB is firewalled, but why pay for extra traffic that's just going to be blocked?