I implemented similar feature in my app https://tarvis.io
Tarvis allows people to self host apps without managing servers. Each workspace gets their wild card cert at *.weightedreply.tarvis.site.
Then when any app is installed by user in their workspace, they get subdomians under that wildcard without leaking what apps are running there. N8n app gets n8n.weightedreply.tarvis.site and hermes gets hermes.weightedreply.tarvis.site.
The proxy and auth is handled by self hosted pomerium so no dns records are published for any app subdomians under that workspace url.
I am using Google certificate manager which is free to generate and manage these wildcard certs. I know Google is not preferred but that's the only free service I could find to do this.