To me having to maintain two separate graphql services for a single API seems extremely convoluted. I can't expose the private api to any other internal services, because all the authorization and restrictions are done on the application layer.
To me isn't that just using a GraphQL server as an ORM? To me that seems like an extremely roundabout way to do something like that.