What we do internally where I work is the following: our application servers all listen only on a secure internal network and accept incoming connections only from our 'gateway' server. All simple HTTP over port 80. The 'gateway' servers run just Nginx and nothing else. They staple SSL and HTTP/2 on top of the forwarded requests to application servers.
Since our gateway servers are stateless and behind a floating IP we can easily swap them out. And because their task is simple we can take more risks with those servers (cutting-edge things needed for HTTP/2). Currently our gateway servers all run Debian Stretch (unstable) since we get Nginx with OpenSSL 1.0.2 for free. Our application servers run whatever stable software they require.
A simplified but functional version of our Nginx configuration: https://gist.github.com/Ambroos/1552515b0dd2b755fe1a