Install nginx, set up generic HTTPS redirects and the .well-known directory. Also acquire Let’s Encrypt certificates for domains listed in the `tls_domains` context property (or just for the primary IP `dns_domain` if `tls_domains` is not set).