Shipping to Production: Terraform, Caddy, and the DNSSEC Disaster

Taking a SvelteKit + Rust blog from Docker Compose on localhost to a live production deployment on AWS. Terraform provisions a single EC2 t4g.micro, Caddy handles automatic HTTPS, and ECR stores Docker images -- all for about $8/month. Then DNS breaks everything: forgotten DNSSEC records silently block Let's Encrypt certificate provisioning, launching a two-hour debugging session across three cascading failures.