

Sure, you could better automate this with OpenBao (not OpenTofu funnily enough)
You’d generate and sign your own root cert. Then manage all following changes with OpenBao as PKIs https://openbao.org/docs/secrets/pki/quick-start-root-ca/
Deeeep rabbit hole here https://openbao.org/docs/secrets/pki/considerations/
I left .world for sh.itjust.works…eyeing db0 tho