The new `-tls` parameter is empty by default, retaining the current behavior (no change).
If `-tls=self-signed` is specified, the packer generates and signs a RSA4096 certificate, stored in the host-specific config directory, e.g. typically `~/.config/gokrazy/<hostname>/{cert,key}.pem` on Linux.
If `-tls=<certpath>[,<keypath>]` is specified, the packer uses the specified certificate and key.
When TLS is used, the certificate/key is included in the gokrazy root file system at `/etc/ssl/{web,web_key}.pem`.
To switch an unencrypted (HTTP) installation to HTTPS, use the `-insecure` flag for the first update, e.g.:
`gokr-packer -tls=self-signed -insecure …`
…then remove it for all subsequent updates, which will now be done via HTTPS:
`gokr-packer -tls=self-signed …`