I was going to say "the FediMeteo people probably have some good ideas there because it's what they do" except it's already right there in the acknowledgements (Stefano Marinelli => FediMeteo).
If I set this up i would just run every service on the same machine sans jails. Are there any practical benefits to doing it like this? The extra complexity buys some slight measure of security in case one service is exploited, I guess?