certs commands support local HTTPS. Generate missing certificate material
through the template’s init service, then explicitly trust that site’s local
certificate authority on the workstation:
certs/rootCA.pem first. Production certificates
should use the ingress component’s managed or custom-certificate workflow, not
a development certificate authority.

