Before we can switch labs proxies to https-only we have to get everything under our one *.wmflabs.org cert.
|Resolved||bd808||T131288 Make Cloud Services shared HTTP proxies enforce TLS|
|Resolved||Andrew||T131290 Abolish use of labs proxies in domains other than .wmflabs.org|
I don't necessarily disagree with Alex's suggestions but I'm nonetheless going to pursue the initial intent of this task for now... once we have things somewhat standardized we can talk about new proxy dns designs. Obviously killing off long-standing domains is hard in any case.