One thing, you don't have to expose that mariadb port, all services in a docker-compose file are on the same network unless otherwise specified (and you can address them by their container name, build-in DNS!) :)
Oh and you can super-power it by Using Traefik for https, you just need to add some stuff to your docker-compose.yaml file. Although OP mentions a reverse proxy already, outside of this compose file.
I wrote a bit about this too with more detail, but I'm too afraid that HN will smash my poor Corei3 server :p. I want to get all of it on GitHub at some point, and then share it.