Hello from S4-F3.
If you are reading this at https://bielefeldt.berlin/, the whole path
works:
- your browser reached the IONOS VPS over the public internet,
- nginx there proxied the request into a WireGuard tunnel,
- the Fritz!Box at home decrypted it and handed it to the LAN,
- and nginx on S4-F3 — a machine with no public address at all — answered.
WIREGUARD-TUNNEL-PROOF-S4-F3