Personally I'm afraid to make anything I'm working on publicly available, in case the server logging at some level isn't compliant. It's hard to be sure something hasn't been overlooked, and the monetary risk is very high.
It's not that hard, unless you're using squillions of third-party services. And that's the kind of thing that GDPR is meant to discourage.
And even if it didn't, the only PII that that would gather is IP addresses (and user agents, but I don't know that those count). It's relatively easy to hit your service from a local IP address with a custom User Agent, then check for that IP address and user agent in all the files on the machine. (Log files are pretty much all plain-text, but you could look for the two obvious byte encodings of the IP address too, if you like. Maybe also check the contents of gz files, but that's starting to get silly.)
¹: Read: I'm basically certain, but I'm not a lawyer and my understanding of the “legitimate interest” basis is not as good as my understanding of the rest of GDPR.
In other words, if there's even a chance that you say no to them (ab)using your data any which way they like, they consider you a net negative to their business.
This is why most US companies chose to just block the EU entirely. No need to deal with it or bad advice like what you're sharing here.
It's possible. I deal with European customers, their lawyers have signed off on my implementation.