@NEETzsche
You're over thinking this.
You have your app server on one VPS or dedi host, and then have an el cheapo VPS actually talk to the internet.
So you can only get a cheap front janny'd. If you have two or more of them, zero downtime.
This is the setup we run on an imageboard I do the tech for. Port 443 is only even opened up for the reverse proxies, *and* we require client certs for them. So you can't scan the (IPv6 good luck) internet for it.
No host on the planet is going to inspect your disks. They'd sooner just get rid of you, if someone told them something terrible was present.
@p @graf