A bit of a mix of the other comments, but I use a generic VPS (I use DO now, used to use EC2, but anything works) with my application wrapped in a Docker container with its port exposed. Nginx reverse proxy to pass from 80 to my container's port. After that is working, I use certbot and it automatically detects Nginx and offers to automatically set up TLS on 443 and redirect 80 -> 443 to ensure connections are coming through HTTPS. certbot is a god send.