The selfhosted guys are correct with that. Of course its not a magic pill, but it can help to minimize the attack surface immensely with little effort.
Edit: while open ports can easily be enumerated, a reverse proxy often requires knowledge of the right server name. In tls1.3 those are not transferred in clear. Depending on your threat scenario you might want to consider doh/dot etc.
Reverse proxies can require client certs, which lift the security benefit to something like a vpn. Even basic auth adds a high threshold to attackers and is simple even for random users to work with. All this is functionality many services don't offer natively - as they assume a reverse proxy anyway I guess.
Didnt find any /s there. That's one of the reasons why I dislike docker, it supports not understanding stuff. But then that's just me, who wants to understand stuff. Enabling less tech savvy ppl is also great I guess.
But you still will not be notified when this changes?
Admittedly the dev maintaining the aur sounds better than random person...