Validation
- Issue: #419 — Add Hetzner edge node as reverse proxy for custom domains
- PRs: #420 (module), #421 (secrets), #422 (4 missing secrets), #423 (OIDC secrets), #424 (ACL + OAuth rotation + apply fixes)
Checks
- ✓ tofu apply succeeded — server + tailnet key created
- ✓ VPS running at 178.156.129.142 (Ashburn, cpx11)
- ✓ Joined correct tailnet: edge-proxy.tail5b443a.ts.net
- ✓ Tailscale ACL grants edge→k8s access
- ✓ Firewall allows 22/80/443 only
- ✓ Cloud-init completed (Tailscale + Caddy installed)
- ✓ All secrets GPG-encrypted in pillar, ~/secrets updated
Remaining
- DNS A record at GoDaddy (manual, post-validation)
- Caddy Caddyfile configuration via Salt (follow-up work)
- palinks/docs/custom-domain.md needs update to reflect Hetzner edge decision