Cannot access cockpit on port 9080

Thats right. Not always but people often do not set it up properly or are using automated scripts they do not understand but which indeed work.
All this can not happen on CloudFlare Certs Thats why I would recommend everyone to use CF Certs on proxied Domains. Also most browsers will trigger an error if someone want to reach a CF Cert directly which can be good or bad. Depending on what you need.

True. A rather common thing.

True, if one doesnt plan on having direct access Origin certificates are the easier choice.

an off-topic reply/question to an off-topic reply: what typically are those server settings that do expose the IP, or rather how does one ensure that one is safe? Firewall and Nginx.conf settings?

