[Internet facing router with up to date firmware] --> HTTPS --> [separate VLAN DMZ] --> [my hardcore IndieWeb VM/k8s/bare-metal whatever] --> [x No outbound access / paranoid local firewall inside the VM x]
[My home computer] --> SSH --> [my hardcore IndieWeb local cloud]
That's about it. Safe enough.