Just my two cents, but there are good reasons why Python web frameworks are encouraged to sit behind a reverse proxy:
- Security, most WSGI servers are not designed to handle bad actors like intentionally slow clients. It is usually trivial for a client to DoS your application.
- Separation of concerns, letting your framework focus on its core job rather than pilling features related to crypto and certificate renewal.
The fact that you struggled getting HTTPS to work probably means that you were heading the wrong direction. I suggest to take a look at Caddy[0]. It is a small, handles HTTPS automatically and is super easy to put in front of a Python application.