I use a cryptomator mount and sync that to whichever cloud i want, but the un/mounting is manual.If you need full disk encryption look at ZFS and snapshots.Do you need to backup everything on the disk?
It's not your computer, i highly recommend you ask for permission.
Especially, I miss the virtual desktop feature,
SysInternals has that feature (Desktops specifically) you can use for Windows 10 (and i think it's native on 11). This is a common feature in most Linux distros...
What i do is work mostly on VirtualBox VMs, but had to have clearance from IT for that (and for USB) 'cos i do all kinds off stuff that triggers their normie warnings.
Even ones that were supposed to just be customer service usually had something they were supposed to push.
True, which i failed to push when i was doing it 'cos the last thing a bitching customer wants is Hey, what about buying a new product? Then i got a real job.
VPN: Headscaleis an open source, self-hosted implementation of the Tailscale control server, which itself uses WireGuard under the hood.
For the file share, i'd say separate into two groups/VMs probably.Whatever you might want to self-host publicly (are you sure?) keep it isolated. Its own VLAN, IP/host/subnet, container, VM heck its own hardware if possible. Or use a VPS and only self-host your private stuff in your LAN.
For what you should host: that's up to you. I've heard jellyfin's used a lot for media stuff.
Atm main sys is a ZFS RAIDZ1 on 3 SSDsWeekly-ish backup onto 1TB external HDD.Sync encrypted important stuff to Cloud.Syncthing some stuff to smartphone.
That usually means there are infiltrated agitators.