Don't expose anything publicly, instead setup wireguard for every VM. Connect your phone, PC etc to the VPN so you have full access without publicly exposing anything.
You may have touched on this but your post was way too long so I only read the headings
Their target market are people they can upsell extended warranties, anti-virus, etc to. So if you're buying individual computer components you already have too much knowledge for them to exploit you
It would be more useful to see metrics weighted per active user it's trivial to update a server if it's just for yourself, and likewise it's easy to let it lag a few versions behind.
What's more relevant is the version number the large instances are running
That's actually pretty reasonable. I'd be happy to make my open source projects compliant for a company - but they can damn well pay me for the effort.
More likely that they know of all the data they gather this is the most privacy defying, and impossible to anonymise so they're fixing it before the EU forces them to.
Don't expose anything publicly, instead setup wireguard for every VM. Connect your phone, PC etc to the VPN so you have full access without publicly exposing anything.
You may have touched on this but your post was way too long so I only read the headings