>> To be sure: will user be redirected by nginx to Gluu Server to authenticate himself directly with fido protocol? Is it necessary to make Gluu Server available for user's direct network connections?
Yes, user will be redirected to Load balancer.
No, you don't need to expose Gluu Server's 443 to Internet, just expose that to Load balancer.
>> And what if U2F device - is the sole authentication factor necessary, should I enable fido2 script instead?
Yes, you have to enable script for enabling Gluu Server's 2FA workable.