34a65e099e
Restructure the ohm vhost from the pre-certbot template into an explicit 80->443 redirect + hand-managed 443 TLS block, pointed at the wildcard cert installed on the VM (/etc/ssl/certs/wiggleverse-wildcard.crt + the key under /etc/ssl/private). Adds modern ssl_protocols/session settings that previously came from certbot's managed snippet. All CSP/HSTS/security headers, root, and locations preserved verbatim. Enables flipping ohm to the Cloudflare orange cloud (SSL mode Full strict). Cert files must be installed before reload; retire the old cert with `certbot delete` once cut over. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>