Automatic TLS for internal only services?

How can I setup caddy for automatic TLS for sites that will not be publicly available? For example, I want to create an app that serves on history.lan which will be some sort of 10.x.x.x address. We can manage the DNS on our internal DNS servers.

For automatic HTTPS? You’ll have to set up your own ACME-compatible CA and then tell your machines to trust certificates issued by it.

