1. Run the server on a public host. Point DNS at it: an A/AAAA record for the admin host, and one for each frontend domain you'll create. The server checks this at startup — if SEIKAN_ADMIN_HOST doesn't resolve to one of the machine's own network interfaces, it refuses to run rather than starting "successfully" and silently failing to ever get a certificate. Behind Docker/NAT/a reverse proxy, where the local interface address is never the public-facing one, set SEIKAN_SKIP_ADMIN_HOST_CHECK=true to bypass the check.
  2. Open :80 and :443 (both required for ACME; :443 also carries the client tunnels, told apart from browser traffic by ALPN) and the TCP frontend range.
  3. Start with SEIKAN_ACME_STAGING=true; once names resolve and tunnels work, switch to production and restart.
  4. The systemd installer runs the server as an unprivileged user with CAP_NET_BIND_SERVICE and a hardened unit (ProtectSystem=strict, syscall filtering, namespace/address-family restrictions).

HTTP/2 on :443 is intentionally disabled (keeps websocket handling simple; little benefit given the single multiplexed tunnel).