I recently found Tailscale when searching to control my home lab when traveling and have been amazed by how simple it is we can create a private network.

Even better: while some public WiFi spots block VPN authentication, Tailscale (if already connected while on a different network) will continue to send traffic.

You can't VPN out of the guest WiFi at my work (using personal device), but Tailscale, if connected while I'm at my house or via phone hotspot, will happily let me use my home devices as exit nodes. So I just leave it on all the time and only disconnect if there are issues (rare). I can use sketchy WiFi without really worrying about snooping, and for services that require me to use a US IP address... well, my house is definitely in the US and it's not going anywhere.

I normally am one to not recommend proprietary services, especially for homelab use but their solution is just so far above all of the alternatives in terms of usability that I make an exception here.