You’re setting yourself up for some future and potentially hard to introspect problems for yourself and your users with this setup. There are good reasons to keep those endpoints separate. As an example, the anycast solution you’ll rely on on that host, while great for short lived tcp sessions (https) will be problematic for your long lived sessions (ssh) which will be disconnected during routing changes in cloudflares network - ddos or operational changes. That is unless you establish sub flows for those sessions using a unicast IP address but now you’re accumulating additional complexity for the sake of wanting it all on a single hostname.