Tailscale. Based on WireGuard. This is nextgen VPN/tunnel/secure way to expose your service. Works out of the box and can be customized as you see fit. Forget expensive cloud vpn to site, you can run 100 clients for free but I would recommend paid services if you are serious. I don't get a dime from them, just happy to share what I use and consider actually useful....
Tailscale is pretty great.
reply
Tailscale was a life saver when I ran a bunch of Kubernetes clusters. Devs always needed to get into the private subnets for things, and the ability to have Tailscale get them into these private subnets without all the OpenVPN shenanigans is awesome.