

You’re right. It is easy to make these comments but it’s also a cautionary tale. It’s becoming increasingly difficult to use something within a “walled garden” but also retain ownership/access of it yourself.
Just having an external HDD for a backup goes a long way.






Solution: don’t run hosted services on your edge appliance.
In OP’s case, I’d use the RPi for the OpenWRT router and the miniPC for any relatively small hosted services I need. That way you can keep your services in its own DMZ away from your IOT devices assuming you have a smart tv/roku/firestick or other random likely vulnerable devices.
Network segment everything you can, but at the very least, I’d keep your services off of the device that is separating your LAN from WAN.