TLS termination moves the trust boundary

Wherever TLS is decrypted is where your data becomes readable, and that place is often not the application.

A load balancer, a proxy or a content delivery network terminates the connection, sees everything in the clear, and then forwards it onward. That is a normal design and it means the protection you think ends at the application actually ends earlier. Whether the leg after termination is encrypted, and who can reach the terminating device, are the questions.

More on TLS and PKI