Just to put a pin in this ,from my perspective, I gave up fighting this on truenas and leaned on Caddy in my OpnSense router. It’s a plugin and there’s a pretty straightforward and well documented workflow on how to get it running.
Only drawback is that everything is using a (valid) wildcard cert for my domain instead of generating a cert for each site. Probably my fault somewhere but it works despite that annoyance.