Certificates that live on a box you patch will expire at 2 a.m. Terminate TLS on the distribution. Use managed Let's Encrypt or upload a custom certificate. Redirect HTTP before origin ever sees it.
Managed or custom
Managed Let's Encrypt covers ordinary hostnames. Custom SSL is for names and issuance you already operate. SNI and TLS version policy sit on the distribution.
Force HTTPS at the edge
HTTP redirects should not depend on the application. Cloud CDN can force HTTPS so origin never spends a worker on a 301.
0-RTT and HTTP/3
TLS 1.3 with 0-RTT shortens repeat connections. Pair it with HTTP/3 at the same PoPs.
Origin TLS is separate
Validate the origin certificate on pull even when the public certificate is managed. Two TLS hops, two jobs.
