Getting a real domain and real HTTPS
Next goal: stop serving this site off a bare IP and get it behind a real domain with real HTTPS.
Free domain
Used DuckDNS for a free subdomain, mileshuynh.duckdns.org. Gotcha: it auto-fills "current ip" with whatever machine is viewing the page, not the server — had to overwrite it manually.
Nginx + Certbot
Changed Nginx's catch-all server_name to the real domain, then ran Certbot with "redirect HTTP to HTTPS." Cert issued, deployed, auto-renewal scheduled — a surprisingly small amount of work.
The mixed-content trap
Switched to https:// and the page lost all styling. Bludit had the site's base URL cached as the old http://ip, so every asset request got blocked. Fixed by updating the URL setting.
A brief AWS billing scare
Watched the cost tick from $0.16 to $0.21 in a day, briefly panicked. Turned out I'm on AWS's credit-based free plan — everything draws from a $100 credit that comfortably outlasts the plan's window.
What I actually learned
"Free" domain and HTTPS are each about 10 minutes once you know the gotchas. Mixed content errors are unusually self-explanatory. AWS billing looks scarier than it is.
Next up: back to the honeypot, see what's landed in the logs.