To answer thread title -
iPad + keyboard, with as much hardening as is possible.
Airplane mode most the time, minimal install and no iCloud signed in.
Further restrict app permissions disallowing mobile network, background refresh off.
Any heavy lifting required I just remote into a windows machine at home which is assumed exposed and just has games /vms on it.
Tentatively awaiting desktop mode to mature on graphene so I can think about moving to a one device set up, monitor and lap dock.