Add to that need to use machinectl to establish normal user session with DBus in it.
But that only makes sense for rootless containers. User management in rootless container and users in roootful containers can get complicated fast and depends on how image is built.
If you are really concerned, buy VPC from large cloud provider, install HTTPS server proxy, configure your web browser to use it. 512MB RAM server will be sufficient as long as it is given enough CPU. Free google instance is suffering from low CPU, not memory.
This way your link between you and internet provider is obscured. Your IP will be shared with others by cloud provider, so you get some obfuscation on that end.
If you use your own certificate authority, then you will get 100% man in the middle protection for link between internet provider and your home. If you use let’s encrypt, then we don’t know that status.
Advantage of this model is speed.
Your browser is still finger-printable, as always.
Securing DNS is its own topic.
You shifted your identity to cloud provider, so it is never 100% safe.
Forget about we keep no logs VPN statements. Judge order and you are logged by VPN provider and don’t know it. So what are you paying for? Slow speed and obfuscation of IP?
I am not saying to install Arch. Just a way to identify your system.
One easiest way to get your old disc back is to wipe out formatting data on new disk. Be warned that running wipefs on wrong drive will loose all of your old disk data in less than one second. So, identify your disc with absolute certainty using lsblk, you may need options to lsblk.
I recommend that route as well.
Since you don’t know much, stick to native services. In most cases those are already preconfigured if native service package is available.