Today you setup you shiny new host and you know exactly what is running on it and what ports are open. Some months/years later?
Yes, a single purpose mail server can get by with tcp/22 and tcp/25 for all it's useful life but something more complex?
Or when you don't even know for sure what are defaults are and you 'move fast and break things'? Should I remind you about MongoDB fiasco? [0] Are you sure all your 'internal' services (DBs and whatever) are bound to localhost and not to 0.0.0.0?
Running a firewall in the default drop/whitelist mode (at least for the inbound traffic) protects you against your own mistakes.
Add to this what while you can be an exceptional localhost admin, as soon as you have more than 5 hosts and/or work with other people you can never be sure what every host is properly configured, secured, don't have anything unnecessary running.
[0] https://krebsonsecurity.com/2017/01/extortionists-wipe-thous...
>> If installed on a server with the default settings, for example, MongoDB allows anyone to browse the databases, download them, or even write over them and delete them.