An easy workaround is setting up a $5/mo VPS to act as a bastion host and relaying all your traffic through that.
My setup has nginx config files for each of the subdomains, each of which does a proxy_pass to some port for whatever the service is. Then my server box hosts like 20 different services, all of which right now I just point to from google domains using dynamic dns.
So instead I would have requests go to... what, an nginx I host on cloudflare?
If you don't want to rely on Cloudflare you can also rent a cheap VPS which you could use as a public reverse proxy which points to your internal reverse proxy through a vpn like a self-hosted wireguard or a service like tailscale. I just did this same exact setup and only had to add some nginx config to get the real IP address of the client instead of the public reverse proxy's.
Either way your own network is safe and hidden from the public.