I have to come back to this... because dockers behind firewalls/NAT there's more to do. And the cert thing fails.
I am not sure I will have time for this before you guys release more, but if so, I am guessing there will be some extra instructions needed on opening firewall ports and then something on the config file that needs to know which ports are being redirected to allow the challenge to be done.
Other than that... nice deployment.