My confluence server is behind a proxy which requires a valid client certificate to talk to the server
I have other proxies which require OIDC authentication before passing any packets on
Now sure, I'm still vulnerable to internal attackers from my company, but that's an audited trail to a real specific user, not just a random botnet on the internet.