I just realised I’m making this much more difficult than needed, currently I am using a Nginx reverse proxy running on the Synology for the internal services.

I’m just going to remove that, install caddy under docker and use it to do the same as it’s on a different machine to the one running the external accessible sites.

No idea why I didn’t think about this earlier. Also means I don’t have to alter my DNS settings on my router as everything will continue to point to the same machine.
