Wireguard VPN server on same hardware as shinobi, security risk?

I have a raspberry pi 4 running shinobi, with a couple of other self hosted elments. its working well. I was considered setting up a wireguard VPN server on the same hardware.

In the shinobi documentation it states

" The VPN Server software should not be installed on the same server as Shinobi if being used for purposes other than monitoring Shinobi.
If your VPN Server is only being used for Shinobi then it should be fine to install on the same server. "

What are the considerations for the set up I am proposing? I obviously have routine security pratices in place iptables, fail2ban ect.

Thank you!

If someone can compromise your wireguard vpn box, they will get in to your Shinobi box as well.

Benefit of separation is mainly for organization for your case.

You can monitor traffic etc from the boxes easier, do maintanance on one reboots etc.

I personally don’t because my VPN is used to access other services than Shinobi

I do this, I’m of the view that docker containers provide the boundaries I am happy with