I think a better option would be to create a Wireguard tunnel between Raspberry Pi and the remote server instead of a SSH Tunnel. Then there is no need to add or change ports and restart the tunnel for every service.
Beware of TCP over TCP issues[0] when using SSH for tun.
Solutions can always be improved, but it's not always worth doing that.
The only TCP in use is the TCP connection of the SSH connection between hosts.