You will want to isolate the Minecraft server because it is notoriously easy to hack. If you can isolate it then Cloudflare is better than exposing your IP and opening ports at least. Tailscale would require registering each client using VPN so it isn’t accessable by anyone except trusted clients, and you’re not exposing ports/IP.
No matter what though, don’t let that server be able to talk to anything else on your network or even the admin login on your router/firewall. Treat it like it contains malware already
I follow various red-team security researchers, like the Security This Week podcast, which has mentioned how easy it makes their jobs when they find a Minecraft server on either the employees network or even a work network.
I’m sure many of the vulnerabilities come from modding like the recent fractureiser virus going around lately. If you kept it 100% vanilla it would be more secure, but at the end of the day you have a platform designed to run modified code, most of which is downloaded from external sources, and you’re going to open that up to the world? I certainly don’t want that within ping’s reach of my home computer or firewall