Prefer a VPN or a mesh network over opening ports. Port-forwarding exposes a service to constant automated scanning, and one unpatched application is enough. If a service genuinely must be public, put it behind a reverse proxy with its own certificate, and keep it on an isolated network segment.