Like I said, an order of magnitude harder than it should be.

It should be install app, do an oauth flow to open a tunnel, done.

Ah, for Tailscale inside Proxmox I'm assuming.

This script exactly works like as you're describing:

https://community-scripts.github.io/ProxmoxVE/scripts?id=add...

Most humans don't know what a script is