Zebra Connections

Goal: Private / Personal lightwalletd server
Background motivation: (I have & shared this concern)

sarahjamielewis: jan, 2021
“I’ll put it out there that my main concern with the current batch of lightwallet infrastructure grant requests is that I think the future needs to ere towards enabling hundreds of low cost, low trusted options rather than *tens of well maintained options with expensive maintenance costs”
source: 2 years of Lightwalletd Infra hosting & maintenance - #7 by chris-remus

When you mean private is “publicly available but for my own use” or “usable only from a subnet of mine”?
Yes. basically I want to run an ec2 instance, zebrad, lightwalletd, install the required certs, open the required security group ports to allow, zingo, ywallet (not sure nighthawk) (zashi not yet) to connect to the ip of the mobile device running the above apps.
My pain points:
Which ports do I need to open in the ec2 instance security groups? For the outside mobile device / apps to connect.
Best location for the lightwalletd ssl cert?
Lightwalletd start up script any additional --flags?
Any other suggestions welcome?