

Firstly, wildcards are convenient but they break your functionality of authenticating the server to which you are connecting which is half of what TLS does. That may or may not be important to you.
Does it work without TLS? Start there, making sure dns and reverse proxy works, works, then add the certificate/TLS termination.





I am neither stating TLS termination is wrong, nor providing instructions to cert pinning.