I’ve opened port 22 to specific IPv4 addresses, like my employer’s, friends and family.
For any other IPv4 origin, its best to set up a VPN. It’s trivial to set up wireguard.
You’re probably safe to open port 22 for IPv6, as the address space is unfeasibly large to be scanned, but still, the secops in me doesn’t like security by obscurity, so I don’t. Also, there’s evidence that hackers use things like IPv6 access logs on NTP to find accessible devices to target.
Ask a friend to hold onto your disks.
Then you can say truthfully, if asked, I used to rip CDs, DVDs and bluray, but I don’t have this material any more, I just stream legitimate content off Amazon/Netflix etc.
But you need to learn how to fool polygraph tests because you’ll still have a “tell”