This example can make sure all requests to the upstreams are handled via HTTPS.
upstream source.example.tld {
server s1.example.tld:443;
server s2.example.tld:443 max_fails=2 fail_timeout=5s;
server s2.example.tld:443;
}
server {
proxy_pass https://source.example.tld/;
proxy_ssl_protocols TLSv1.2 TLSv1.3;
proxy_ssl_verify off;
proxy_ssl_session_reuse on;
}