I second the complaint about subpaths. I have all my services on a single domain, except for HA. It's for security by obscurity, when you issue a certificate for a subdomain you start getting malicious traffic probing for vulnerabilities almost immediately. I don't have this problems for services with non-obvious subpaths.
I can't understand the stubbornness of developers to accept patches for fixing this problem.