Adding to why it has to be reachable: when a local user follows someone on another server, that server pushes new posts to your server's inbox, so the remote side has to be able to resolve your domain and connect over HTTPS. A LAN-only box can't receive that.
The least painful compromise is a cheap domain (or a subdomain you control) plus a tunnel or a small VPS acting as reverse proxy, so nothing on your home network is exposed directly. Then close signups so only your household can register. If Mastodon feels heavy for a handful of users, GoToSocial is much lighter on RAM for that use case, though you'd use a separate client app with it.
One thing to decide up front: the domain is baked into every account and can't be changed later without starting over.
For your points 2 and 3 specifically: if you go the Icecast route (AzuraCast also uses Icecast under the hood), Icecast can require a username and password per mount point, so the stream URL alone is useless to anyone who stumbles on it, and you can give the mount a bland name. Put it behind HTTPS on your reverse proxy so the password isn't sent in clear text.
For point 4 (genres at certain times), AzuraCast's playlist scheduling handles that from the web UI. If you build it yourself instead, Liquidsoap can switch playlists by time of day, but it's a scripting language with a learning curve.
If what you really want is your own library rather than one stream everyone hears at the same time, the Navidrome suggestion is simpler: separate logins and plenty of Subsonic apps on Android.