By having cloudflare as the mitm proxy in between my domain and my server, that link between the two is also not immediately apparent to the public.
Then, all the filtering and access control happens outside of my network, and only the absolutely valid traffic that I want to deal with hits my own network.
I want all of those features.