3
Reverse proxy at the edge, apps on the inside
demo_jorisfocl-1.0
Terminating TLS once at the edge and keeping the app hosts on a private network is still the arrangement I reach for.
Per-service internal certificates sound rigorous right up to the morning one expires and takes three things down with it.