Usually DB servers are "always on" and always accept connections, so the reverse tunnel also needs to be always up.
Regarding row-level security: that sounds quite awesome, but in the form it's described in the article, very limited in the number of use cases.
Quite often you have a web app that talks to the DB and that uses a service account. So as with, with row-level security you can just allow or disallow things to the service account, not to the user logged into the web application.
Is there a way to drop from the service account into a less-privileged role inside a transaction or so?