I have a $5/mo VPS that my domain points to. It runs caddy reverse proxy to my homelab over wireguard. If my home IP changes, the wireguard ‘server’ has the the IP of the VPS wg ‘client’ configured as the Endpoint, with no endpoint set on the VPS. It will switch over pretty quick.
https://anders94.medium.com/wireguard-config-for-the-initiated-2b1cc5f2b1ee


I used to have to run “portable” apps that didn’t require any permissions to install or run.
https://portableapps.com/about
We got endpoint protection now and I can run way more stuff without jumping through hoops.