If you are somehow completely unable to run a proper certificate on the origin (EC2 instance(?)), and thereby Full (Strict), my suggestion would be to switch the set up to run over a Cloudflare Tunnel instead.
Even then, if seeing the origin IP of yours leads to a security issue of some sort, I would go as far as to say you have other and more serious problems that you should solve first.