Hello, so did you use the private internal network IPs on the published ports for traefik, so that every app is accessible internally, and obviously not publicly, from traefik? And then point dns to the nginx vm, and set it up to reverse proxy to the traefik instance, with rules only for the desired sites that you want to be public? Thanks