Tunnel is fine security wise. Keep the reverse proxy anyway and let the tunnel point at it. Routing, logs, etc. stay in one place this way.
Zero Trust with Google etc. is the way for family. Tailscale or Wireguard means installing a VPN client and making sure it keeps running, that’s too much for most people who just want to click a link.



It works but I wouldn’t call it the cleanest solution, more a workaround. As far as I know only apps targeting SDK 37 are affected, older apps still get the permission implicitly. So the proper way would be to just grant “Nearby devices” to the apps that need it e.g. Immich or Jellyfin and if an app doesn’t ask for it that’s actually a bug and worth reporting, because it should request the permission as soon as the server resolves to a local IP. I also find the “Nearby Devices” title a bit misleading for apps that only need it to reach your own server, but on the other side it gives a somehow proper hint what the permission actually allows.