True, in the literal sense that you will have to administrate your own system, but I'm sure there must be ways to make this easier for people. Perhaps small computers that come pre-configured with the correct specifications for being a good small-scale server and pre-installed with software that provides a simple web GUI dashboard that you can just drop files on and it will serve them up for you, with everything else taken care of under the hood.
> applying software updates all the time
With image based distros, containers, and their respective auto-updating schemes, this — and the concomitant problems updates may bring given the extensive and hairy state of most systems — should hopefully become a thing of the past.
> patching emergency security vulnerabilities
I mean, unless you are running something that is incredibly visible online and linked to you from a lot of places or used by a lot of people and so you need to take extreme extra security steps, shouldn't this be taken care of by just regularly updating your software? For a small scale self-hosted blog or personal email server this seems a hardly proportional.
> hardening services against constant attacks
Again, it seems like you are projecting the requirements of a much larger scale endeavor onto small-scale personal self hosting of a blog or email server only you use. And to the degree that system hardening is necessary for a small cell posted system, once again image-based operating systems with hardened Pam authentication rules that run everything in rootless podman containers and keep SELinux enabled should be more than hard enough and all that can be configured and set up upstream to the user.
> deciding whether the daily "I have found a bug in your system and will disclose" mails are legitimate threats
What are you even talking about here? For the third time, it seems like you are projecting the requirements of a much larger scale thing onto small-scale personal self hosting.
> If you fail at any of these tasks, relatively new regulations mean various governments can fine you more than your net worth over failing to report a data breach to the right agency on the right timeline
A data breach? On a small self-hosted blog or email server? Who's data would those regulations be punishing you for leaking, your own, maybe two freinds'? And those regulations, if you are speaking about the ones in the EU that I am thinking of, have pretty clear cut offs and requirements and stuff that really wouldn't apply to someone's little self-hosted thing.