Custom domain for deployment - TLS certificate

I want to have a custom endpoint that redirects conditionally to the closest Elasticsearch deployment to improve the latency of my Elasticsearch cluster in different regions.

I have deployments in US and in Singapore. I manage to create DNS rules to redirect US requests to the US deployment, and other requests to Singapore deployment.

However, in order to to work with I need to connect with HTTPS, hence I need to set up a TLS certificate. More than a year ago this question was asked there and the team mentioned the feature is not supported.

How can set up TLS certificate in ?
Otherwise, what is the best practice to route client requests to the nearest Elasticsearch deployment?

Thank you

