Reasoning behind in/out/fwd netfilter rules

Here is @stgraber post about this

This is why we are hesitant to change the approach at the moment until we can see how other firewall systems approach coexistence when using native nftables (rather than just calling the iptables shim).

I had proposed something similar to your suggestion previously