NATS tls:// + token and OpenBao HTTPS via the ACME wildcard cert (expose.tcp.tls), no custom CA. civil + primer both cut over; plaintext rejected on both. Server config + unseal.sh are instance-side (/data/castle, ~/.castle).
NATS tls:// + token and OpenBao HTTPS via the ACME wildcard cert (expose.tcp.tls), no custom CA. civil + primer both cut over; plaintext rejected on both. Server config + unseal.sh are instance-side (/data/castle, ~/.castle).