Don't the proxies just point back to the main infrastructure? How do the site operators deal with bandwidth usage and QOS and all the edge vps/proxies?
Generally, something like a nginx reverse proxy is pretty performant. The opsec gains come by rotating the infrastructure you run on. If you had something like a ingress -> middle -> backend, and then regularly changed hosts, by the time someone is able to get a court order to seize the ingress, you've already moved on and they need to start the process over.
In terms of system hardening, since the outer machines are almost bare, they are hard to hack. Attempting to attack the backend server isn't easy either (assuming the the webadmin knows what they are doing. Things like blocking outgoing traffic and configuring the system to not leak the backend server's IP)