Your English skills beat those of native English speakers I know. Dont worry there. It's not perfect, but I envy your ability to make yourself understood in a foreign tongue.
I don't disagree, and I am one of the VPN advocates you mention. Generally there is no issue with exposing jellyfin via proxy to the internet.
The original question seemed to imply an over-secure solution so a lot of over-secure solutions exist. There is good cause to operate services, like jellyfin, via some permanent VPN.
Over the top for security would be to setup a personal VPN and only watch it over the VPN. If you are enabling other users and you don't want them on your network; using a proxy like nginx is the way.
Being new to this I would look into how to set these things up in docker using docker-compose.
Set aside a few weekends and mess around distro hopping. Think of it as a small scientific study. Use what you determine to be the most comfortable.
I suggest being clever in your partitioning keeping /home and any other areas personal to their own partition if not their own disks. If you want to experiment you lose nothing by wiping / and installing something else. Also, you should decide on an effective backup strategy.
As good as it would feel to support this sentiment, every one of these "antivax idiots" that catches covid gives the virus more generations to mutate. Creating a danger to us all.
If you wanted to go overboard, don't even make the server accessible publicly. Distribute keys to a Wireguard network that is accessible publicly. Mandate your players obtain keys from you to play.
It's a punitive system, not a rehabilitative system. Americans still believe that punishment is the only way to handle deviancy. Most believe the punishments are not hard enough, this is the "tough on crime" take conservatives have been running on for decades.
The point of interest is what happens when those extremists are accused of crimes. Suddenly, exceptions should be carved out for them.
Make 2 partitions, put veracrypt portable exe on the first normal storage partition. (fat32 is likely ideal here) Second partition formatted with veracrypt.
Your English skills beat those of native English speakers I know. Dont worry there. It's not perfect, but I envy your ability to make yourself understood in a foreign tongue.
It's marvelous.