Your vps isn't doing anything useful security wise.. it's just sending traffic directly to jellyfin.
You'd get the same protection with just port forwarding to a local proxy in front of jellyfin. Or you could even leave out the proxy if you didn't need it.