Is port forwarding to a home server a bad idea?
It is a decision, not a mistake, but the safe version has three parts: no admin interfaces exposed, automatic updates on whatever is exposed, and a separate VLAN so a compromise does not reach the rest of the house. A VPN or a tunnel avoids all three questions, at the cost of client setup.
What is the minimum backup for a home server?
The data volumes and the compose files, nothing else. Containers are rebuildable; the database and the uploads are not. A nightly restic snapshot to a second machine plus a weekly copy offsite covers the realistic failure modes: disk death, deletion, and theft.
Is there a simpler version that gets most of the benefit?
Yes: do the first step, skip the automation, and revisit in a month. Most of the value is in the first step, and most of the cost is in making it repeatable before you know it is right.