It's behind my firewall/VPN (not publicly accessible).
The official instructions use nginx as a reverse proxy. If you don't want to set up something like Wireguard, you can use HTTP basic authentication[0] to make it inaccessible/invisible without a username/password. (You definitely want to also set up certbot[1] for SSL if you go this route.)
[0]: https://docs.nginx.com/nginx/admin-guide/security-controls/c...