

Well yes, it is one hop, because you’ve got the router doing TLS termination. Inside your network you point to the server that has the TLS certs. Outside of the network you do port forwarding, or use a tunnel with cloudflare agents.
Why is the router involved at all? It’s all local traffic. The external traffic comes through the cloud flare tunnel, right? Maybe I’m not understanding the architecture you’ve got.
If you don’t have young kids, you don’t get sick nearly as often. It’s not like having a sick kid at home is a vacation. I don’t begrudge my coworkers their time off for illness or supporting family members with illness.