Opnsense firewall at perimeter...and that's about it. Chances of anything getting in with no exposed ports is pretty slim so I don't really bother with anything more.
For SSH exposed servers/VPS I do change the port though. Cut down log noise & maybe dodge the odd portscanner or two
Expecting a minor revolution on the intersection of /r/selfhosted /r/LocalLLaMA and /r/homeassistant
The self-hosted AI tech is slowly but surely getting to a stage where it could pull all of this together.
What required siri/alexa last year will soon be on /r/selfhosted turf