

I have my home server behind a wireguard vpn access.
While I am no security expert, or precisely because of that, I still try to follow security best practices for the internal setup if I can.
Of course you propably do not have to be as vigilant as if your services were publicly exposed. But I believe it is still a good idea to have some “defence in depth” and not assume only one possible attack vector, e.g. what if there already is a bad actor on your home network maybe via a trusted device that has some virus. Also a plus is i guss if you ever decide to expose something later on you wont have as many issues.



One thing to note is that you are not alone with this feeling, in fact when I read your post it really remindend me of the song ‘I am Machine’ from Breaking Benjamin if you like Rock/Metal music.
Also if you do not want another cosmic scale existential crisis, please do not look up the meaning behind my username ;)