In my case I just don't expose them to network at all, any interaction happens through bots in IM or on a tablet at home (through wireguard).
Theoretically locking it down with OAuth on proxy level would also work, but I prefer to keep it off the internet (apart from the tunnel, obviously).