To access things outside of your LAN (for example from your phone while at the grocery store), each service gets a DuckDNS entry. "service.myduckdns.com" or whatever.
Your phone will look for service.myduckdns.com on port 443, because you'll have https:// certificates and that all happens on port 443.
When that request eventually gets to your router and is trying to penetrate your firewall, you'll need 443 open and forwarded to your Debian machine.
So yes, you have it right.
Also forward port 80.
I use apps on my phone, but have no clue how to troubleshoot them. I have programs on my computer that I hardly know how to use, let alone know the inner workings of. How is running things in Docker any different? Why put down people who have an interest in running things themselves?
I know you're just trying to answer the above question of "why do it the hard way", but it struck me as a little condescending. Sorry if I'm reading too much into it!