Its less of a hassle to use something like nginx reverse proxy docker container in front of your web services, as it comes preconfigured with some best practices regarding TLS. (TLS1.2+ only by default) https://hub.docker.com/r/jwilder/nginx-proxy
If you use docker, be sure to google around how to manage firewall with containers (must use DOCKER-USER chain instead of INPUT)
Ofcourse, you will get a bit involved in setup step if you choose to tie nginx proxy, letsenccrypt and nextcloud containers. But search engine is your friend.
I now keep my primary 'work' and 'private' collections (10-30g each) and a large shared set (350g) synced across desktop & laptop, and also 3 off-site archive servers, using Syncthing. This includes a literal satellite connection for one site.