Well yes, it is one hop, because you’ve got the router doing TLS termination. Inside your network you point to the server that has the TLS certs. Outside of the network you do port forwarding, or use a tunnel with cloudflare agents.
Why is the router involved at all? It’s all local traffic. The external traffic comes through the cloud flare tunnel, right? Maybe I’m not understanding the architecture you’ve got.
It’s also possible that he (or his advisors) see Canada as a vassal state that should adhere more closely to the desires of their overlords in Washington. The technicalities are significant, but putting the right politicians in the right places would achieve their goals equally. It’s not like the USA hasn’t done this before with other countries.