You start a container that runs just tor with a config and can read the routing endpoints from your config, or link to localhost:2375
HiddenServicePort <onion port> <host>:<port>
You setup HiddenServiceAuthorizeClient with stealth auth type and a list of authorized clients.
You can lock your firewall rules down as the hidden service only requires outbound to HTTPS.
On the client end you setup regular Tor with HidServAuth <onion address> <auth-cookie>
With stealth auth other tor users won't see the serivce and port published without the auth cookie
You can then use socat to bind the remote hidden service and port to a local host and port:
socat tcp-l:127.0.0.1:2023,fork socks4a:onionaddr.onion:localhost:23,proxyport=9050
You then have the remote ssh server available locally with no public interfaces, no public ports, and an additional layer of confidentiality and authentication