At the same time, I hate Apple the least of big tech, since they actually do give a crap about building good products and have done quite a bit of that.
That's an incredibly low bar. There are exceptions of course but I'd argue there really is no need to use "big tech" software much of the time. Smartphones are probably the most challenging, but desktops and laptops? Easy to avoid.
Just to add to the other comments, you probably want to use a wildcard cert so you don't need to individually certify each subdomain (or expose them at all).