

Yes in zero trust > access controls > applications you can specify a web site and then tell it how you want it protected. In its most basic form you can have it email you a login code, but if you link it to either google or Microsoft you can have users of those services use them allowing you to sso straight through.
You can also specify a wildcard *.mydomain.net and then by default anything that is in your domain will be protected. Means when you’re testing something new you won’t forget to lock it down.
You’re correct about media, I use nginx proxy manager for emby, but everything else goes through the tunnels
As for configuring, the cloudflare LLM bot has been trained on all its documentation so it’s one of the few times a chat bot is genuinely useful.

+1 for cloudflare tunnels. But if you want to host locally, nginx proxy manager has a very intuitive gui you’ll be able to host your sites on.
Example:
Docker container exposes port 8989 for sonarr. Nginx proxy manager entry will be: Sonarr.mydomain.com > http://192.168.0.50:8888/ There’s a setting to allow ssl for your domain.
In your domain registrar, just put the a record for sonarr.mydomain.com to the local IP of nginx proxy manager, in this case let’s assume it’s the same IP as sonarr.
So now in your house your computer calls the domain, your dns server responds with 192.168.0.50. That’s the IP of your proxy.
Your proxy gets your request. Sees you’re trying to access sonarr, and passes your query along to it.
But like I said, cloudflare tunnels removes ALL of this and even supports google / azure SSO to keep you secure and keep logins convenient.