- consider reloading (parts of?) config on SIGHUP, at least to update allowed users
- fork/vendor
go-passkeysor ensure all PRs have landed - migrate to
encoding/json/v2once it is out (additionally, ensure no unknown fields + no trailing data) autocert.NewListenercaches certs under an OS cache/temp dir;autocert.Managerwith an explicit dir could be better- consider custom ACME server support