
Install incus on your OS of choice to manage LXCs and VMs, it’s ideal!
No need to chain yourself to an OS that is rolling on the free branch, get stability and control!
As for LXCs vs Podman containers, seems it is preference of control. LXCs are little OSes you need to keep up to date, containers need to be rebuilt to keep up to date. (I think only Linuxserver images actually rebuild just for base OS updates, hopefully the reverse proxy and authentication images too)
Podman brings some nice networking, read-only features, and user abstraction with it, I think that helps it push ahead.
That said, LXCs are little OSes and that flexibility can be very useful. For instance, incus is able to make an LXC with a unique Mac from an Ethernet adapter - I haven’t cooked how to do that with Podman yet. So I run my DNS from there so it doesn’t mess with my server’s DNS port.

I have an admin account on the server and an SSO admin login for the services. Different credentials obviously - ones an SSH key and ones a password/passkey for SSO - but it seems to fit well. My regular account is bozo level and I don’t need to worry much, I just logout or go to a private window to do admin for an specific program, which is rare but easy enough when it’s needed.
So far for the SSO services with an admin account design, I just set it up so the admin account for the service is named the SSO admin account so it maps directly when I connect the SSO to it.
And I SSH into the server for admin there as needed.
And no mixing with my regular user account!