I'm using caddy because it takes care of Lets Encrypt TLS certs. I'd use HAProxy but I don't know if it can do this without additional scripts.
I do have an haproxy setup that does the right thing with LetsEncrypt, but it's just a path-based forwarder that works with an acme script on the system, not directly built in.