I feel old I just open a port for https on my 24x7 raspberry pi and route anything I need through that, for home access, openHAB, etc.... haproxy can look at the beginning of the packet to see if it is ssh and forward that to a server with mutualTLS, and with ssh you can forward anything you want back. If its TLS it goes to nginx which is locked down by vouch-proxy. fail2ban runs in the background to limit abuse - you do need to set up transparent proxying to keep the real IP but it's easy to do. A benefit to this method is you can also do SNI routing and get free wifi in some places :-)