A static server should have one obvious root
One root, one file_server, and a small header policy make a static deployment easy to inspect.
One root, one file_server, and a small header policy make a static deployment easy to inspect.
Use SNI, inspect the public certificate, and alert before renewal becomes an incident.
Test compressed and uncompressed requests separately so caches and validators describe the bytes actually served.
Start with a narrow policy, then expand it only when a documented feature needs another resource.