plateee@piefed.social 2 weeks ago You could either set up DNS overrides on your inwards facing DNS server, leaving external resolution to something like cloudflare (with DDNS), or you have a second internal domain for internal resolution.
I chose the latter for my homelab - it’s service.lan.fqdn inside and service.fqdn on the outside. Since I use a wildcard cert, it’s still protected with TLS if I access it internally or externally.