# Cloudflare's free certificate only covers *.domain.tld and domain.tld - so not *.*.domain.tld which is what you need here (double wildcards aren't valid in certificates anyways)
# You can buy ACM to get a certificate for *.secure.domain.tld, unproxy it so it doesn't go through Cloudflare or change it to appname-secure.domain.tld