Simplest way to get HTTPS in front of a few home services?
Caddy, because certificate handling is the default rather than a plugin:
archive.example.com {
reverse_proxy 127.0.0.1:8080
encode zstd gzip
}
That is the entire configuration, certificates included. The equivalent nginx setup is four times longer and needs a separate renewal timer that fails silently.
Is port forwarding to a home server a bad idea?
It is a decision, not a mistake, but the safe version has three parts: no admin interfaces exposed, automatic updates on whatever is exposed, and a separate VLAN so a compromise does not reach the rest of the house. A VPN or a tunnel avoids all three questions, at the cost of client setup.
Does this still hold if I am working alone?
It gets easier, not harder. A fair share of the difficulty is coordination, and that disappears. What remains is remembering your own decisions, which is what writing them down is for.