Served by nginx from a ConfigMap, behind a Network Load Balancer, over a Let's Encrypt certificate issued by cert-manager.
Edit configmap-html.yaml and reapply to change this page.
nginx reads it from a mounted volume, so a rollout restart picks it up:
kubectl -n website rollout restart deploy/site.