OptionalalpnALPN protocols (or "http3", "http2", "http1")
OptionalcertificateCertificate tags to select (any_tag)
OptionalcipherCipher suites to allow (or "modern" for recommended suites)
OptionalclientClient authentication mode
OptionalclientClient CA certificate files
OptionalcurvesElliptic curves to allow (or "recommended")
OptionalprotocolMaximum TLS version ("1.2" or "1.3")
OptionalprotocolMinimum TLS version ("1.2" or "1.3")
OptionalrequiredCertificate tags required (all_tags)
OptionalsniSNI hostnames to match (e.g., ["example.com", "*.example.com"])
Options for building TLS connection policy