point ingress for certain directly hosted sites ... to the sites.
other things might be DNS like would be normal for S3 but it
still would need to be in the wildcard tls so it's easier to just
do this centrally. I am one person, after all :D
this makes more sense as a wildcard A record, I think. not 100%
sure but for now, we'll try it. I'm pretty sure I don't need this
externally ever, so making this hit the node ports seems right.