I have a Flutter Web app hosted in S3 and distributed with Cloudfront via HTTPS. This web app is an IoT dashboard used to interface with my devices which are running Jetson NX's in an enclosure with a 4G WiFi router (so each device advertises it's own WiFi network). The web app is usually accessed to view the usual dashboard stuff remotely via API Gateway. But if a user is nearby one of the devices and connects to the devices WiFi network, they'll find that the Jetson is running a Flask server that lets them request live telemetry from the device over the local WiFi.
This all works fine locally during development and using HTTP. But so far I haven't found a clear way to get it all working in the HTTPS distribution without users seeing security warnings about dodgy self-signed certs. How can I get this Flask server setup with HTTPS that doesn't generate any of those security warnings, ideally with AWS resources that I can easily manage without involving one of the 3rd party cert providers?
EDIT - Ok after a bit more tinkering I've narrowed down what help I need here. Here's the scenario I'm designing for:
- User with web access browses to mywebsite.com where they get served my Flutter app via Cloudfront with HTTPS.
- User connects their device to the WiFi network being broadcast by one of our IoT Things (this local network may or may not have internet)
- User clicks a button in the Flutter app which makes a GET request to jetson.local:5000/getImage, where I have a very basic Flask server running on the Nvidia Jetson that's running onboard our IoT device. That flask server simply just has a /getImage resource that returns an image from the IoT device.
If I leave the Jetson's Flask app configured to HTTP, then I can successfully view these wifi images if I go to mywebsite.com and edit my Chrome preferences for that domain to allow Mixed Content (allow the HTTPS served Flutter app to make HTTP calls to the Flask server). But I'm looking for a solution where I don't need to tell users to edit their browser preferences.
It seems that the only way around this is to configure the Flask server on the Jetson to use HTTPS. But how the heck do I generate certs to run on a 4G device like this that's regularly changing it's public IP or is not online at all? I'm trying with LetsEncrypt but I don't know what domain name to use when requesting a cert, or how LetsEncrypt would be able to verify that domain (of my Jetson?).