In home environement, it's not often that someone will try to snoop on the traffic, however, the risk 0 never exists, personnally, I've set up SSL using NGINX Proxy Manager and self-signed certificates signed with my own CA, I use a script to generate new certs if needed, so it's not too hard to do (It all uses openssl)
The only "issue" would be to put the CA on all your devices if you don't want the security warning.