Earlier quoted context omitted.
Any reason you don't use some kind of VPN solution for that instead?
Hidden services are very easy to configure (the basic config, if you want to be as anonym as possible you have to do more). Install tor, add a few lines to config, done. And: You don't have to change your firewall settings at all. Nothing is exposed to the clearnet. You can also make your service be accessible only to certain clients which have a certificate. I consider this very secure.
It is centralized, yes, but it is way, way faster if you care about latency
(you can also self-host it with the open source “headscale” project)