OP, what you’re describing is not the “big scary MITM” attack vector. It’s how TLS/Reverse proxies work. Whether you are using Cloudflare or hosting your own reverse proxy somewhere with full control, it’s still terminating TLS at the endpoint and passing back traffic in the clear to the backend.
Some people like Cloudflare for whatever reasons, and that’s okay. I host my own reverse proxy out on a VPS and it works just fine.
You’ll find that not all of the seflhosted community is super-focused on privacy as say r/privacy is.
I was never radicalized myself. I’ve always self-hosted. I spent time in centralized ecosystems like most here, but ultimately I still self-host because I like to have some level of control