566732a02c
Add a general environment.snakeoil-certs module that generates self-signed certs at runtime (oneshot service + daily timer, idempotent via x509 -checkend). Terminate TLS for vaultwarden with nginx on port 8001 -> 127.0.0.1:8000 using a snakeoil cert, so it's reachable over the tailnet IP without the broken public reverse proxy.