V2 Get it working with internal CA in systemd?

Also, why is this needed? Usually this is an anti-pattern or a yellow flag. I wonder if we can simplify your setup and get you down to 1 instance.