When HTTP services are registered (where Central terminates TLS),
reconciliation now checks for and provisions TLS certificates:
- Derives gateway domain from central domain (e.g., payne.io)
- Checks for existing wildcard cert (*.payne.io)
- If no wildcard exists and Cloudflare token + operator email are
configured, provisions one via certbot DNS-01
- For services outside the gateway domain, provisions individual certs
- Services with TLS passthrough (k8s) are skipped (backend handles TLS)
- Graceful: skips silently if no Cloudflare token or email configured
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>