For me, the necessary firewall changes consisted of using "domain (ip ip6)" in ferm instead of "domain ip"; the general config is a few lines in radvd.conf plus a static IP on the LAN interface (and v4 requires that one too). None of that seems very crazy.
> the number of layers of encryption I'm hitting (I'm IPv6 on a VPN using wireguard tunnels and browsing in SSL on my remote machine) seems nuts.
This is two layers, one of which you introduced yourself and neither of which have anything to do with v6.