Domain-level forward-auth needs its own external_host domain when the IdP core and outpost are on different hosts. sso.hubris.network -> Caddy -> LAN outpost. Includes the redirect_uris-regeneration gotcha. Carry the DNS record into Technitium in DNS Phase 2. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>