Thank you for posting this, I was looking to post something similar albeit with far less detail.
I want to sign up for Cloudron and pay to support the developers and have all the conveniences as I have run two free instances for years.
The bit I cannot get past for now is the openness of the apps on the platform. Like Immich is just out there on the web and the security of that instance comes down to the devs at Immich?
I currently use Pangolin for anything non Cloudron related and it gives me a sense of security because things like Immich just aren’t reachable unless you first authenticate to Pangolin. Pangolins job is to secure things and this is what they have built and focus on. Where as Immich works on how best to handle your photos.
Right now I find it scary that my Immich or Outline instances for example that contain personal data might be exposed to the web with little protection.
Maybe I am over thinking it or have my details wrong but it’s currently holding me back from using Cloudron for my personal use and trusting it with my data.