So, here's the thing. Using a cname, that will 'work' but only if you don't mind that the cert is still gonna be for nostr1. The other option is you have a proxy that serves SSL for mleku.dev and reverse proxies to the nostr1 url..
I can't add wiki.mleku.dev to my cert chain because .. reasons.. tho I could look to see if it's theoretically possible..