I don't think it is an issue, however essentially the more restrictive setting (Cloudron or app) will hit first. Looking at the changes at vaultwarden, their defaults are a lot more restrictive than the ones we have set in iptables as a generic default.
I also think this makes much sense. Some apps may require more stringent measures others don't. So while having a basic line of defense from the platform, the apps can add on top where applicable, since only they know which routes to protect more and which are for example just public routes which just have to be prevented from a denial of service attack.