I don't like having <something>.defang.app as the domain defang points to. That creates a dependency on something owned by Defang, which isn't ideal. As a user, part of the benefit of Defang vs other solutions is that it generates nice, self-contained infra in my cloud account. This external dependency breaks that.
Ideally defang cert generate should print the load balancer's static IP address that we can use in an A record.