

Filling some gaps:
systemctl enable --now firewalld unattended-upgrades
Read through /etc/firewall/firewalld.conf, especially the part about how containers might bypass your firewall if you don’t change defaults.
Also rootless podman should run well out of the box as a mostly drop-in replacement for docker (meanwhile docker also does rootless now) and allows you to run the container runtime unprivileged. This is more secure than adding user to docker (effectively root) group. Setting up autostart by writing systemd .service unit files works the same for both Docker and Podman.



There are a couple of threads on ServeTheHome forums where people share experiences. Do consider the security aspect. I’d personally feel wary of exposing any of them to public internet. Even if you don’t believe in backdoors, it’s likely you won’t receive future security fixes for firmware.