

Personal solution:
- Openssl certs (lots of youtube videos on best practice there).
- nginx reverse proxy manager
- adguard home using the dns rewrite pointing to the wildcard domain.
This is enough i find for intranet use. You can get fancy and put it over a wireguard or tailscale network too.




I think they offer unique ips if you request.