How should a mirror be set on AWS, should the certificate be managed by the instance, should we have a domain to each mirror?