Decides where TLS terminates for a generated or adopted Spring Boot project — at the edge (ingress, load balancer, Caddy) or in the embedded Tomcat, with mutual TLS as a recorded variant — and writes the matching configuration: forwarded headers and trusted proxies, or an SSL bundle with reload and profile-gated TLS; HTTP/2 on; HSTS with exactly one writer; the integration test that proves it on a real server; a local Caddy edge through docker-architect.