nottelling
Yup, was a Garmin. Part of me has been a little worried cause i can't find my way anywhere without GPS anymore, and Google has been getting shittier every day.
Hell, I remember the first time I used maps on a computer to plan and print a route, and the first time I could do it online with MapQuest.
Those were moments that the Internet really felt like the future.
The answer to your overarching question is not "common maintenance procedures", but "change management processes"
When things change, things can break. Immutable OSes and declarative configuration notwithstanding.
OS and Configuration drift only actually matter if you've got a documented baseline. That's what your declaratives can solve. However they don't help when you're tinkering in a home server and drifting your declaratives.
I’m pretty certain every service I want to run has a docker image already, so does it matter?
This right here is the attitude that's going to undermine everything you're asking. There's nothing about containers that is inherently "safer" than running native OS packages or even building your own. Containerization is about scalability and repeatability, not availability or reliability. It's still up to you to monitor changelogs and determine exactly what is going to break when you pull the latest docker image. That's no different than a native package.