You can’t go wrong with a 2-bay Synology 🤷🏻♂️ yes TrueNAS is more “selfhosted”, but the Synology is way easier.
There’s also Infisical if you don’t want to run Vault
https://github.com/Infisical/infisical
I personally use Ansible to deploy my .env files to my Docker host. The .env files are encrypted in Ansible Vault and deployed to the server as chmod 400 so only I can access them.
Lemmy.world is run by an actually competent admin who has experience running other Fediverse software.
It’s called CIDR notation
https://en.m.wikipedia.org/wiki/Classless_Inter-Domain_Routing