Your approach is nice and easy and sensible. I personally preferred hetzner to linode (which has a history of bad security) but I imagine the minimum price is higher. When you’re ready to reduce prices and increase privacy, take a look at a tiny (like t3a.micro or .nano) ec2 instance that forwards to/from your “real” server at home which can be beefier. The home server maintains a vpn connection to the ec2 instance.…
The only thing I don't have from your scenario is a public IP due to being on Starlink as I said, so there's no way for me to let anyone in my front door here even if I was willing to endure the pain, which I don't think I am. Is there a way to have my server always be the initiator of the VPN connection, and the bouncing server just say "sorry" if the home server isn't responding?
I am tempted to bring up the question of having a CDN cache (or whatever the terminology is) for those occasions, but that sounds like money, in the final analysis the straightforward setup might still be my best bet for now.
But yah, the idea of just having a small public bouncer that forwards stuff and doing everything from my home servers has occurred to me before, I just don't know yet how to set that up and I get nervous with anything public, it's a scary world out there.
Doing it the "dumb" way just gets me onboard and I can start looking at all the little parts, it's how I learn stuff really... like I said, very interested in doing some more reading on exactly how one would implement that, as detailed as possible because I am very stupid when I'm first setting out on something, I need the text equivalent of someone talking real slow like I'm five. :>