@rgegriff You could always do a Wireguard connection back to a VPS. Or an SSH connection back to a VPS (to avoid needing port forwards).
Chances are, a bunch of folks have already done something like that with a shell script. Seems like a common tool to need.
For your use case? SSH over Tor. That's what I do with my stuff. Ansible works, too. Very few moving parts, easy to set up, set it and forget it.
If you don't trust the tailscale control server, there is a selfhost version called headscale. Theres also apps for it, so you can include phones and tablets into the private network.
A bunch of technomancers in the fediverse. Keep it fairly clean please. This arcology is for all who wash up upon it's digital shore.