SRV records could work for alternative ports, but those websites wouldn't be able to get Let's Encrypt certificates without talking to the API of their DNS provider. ACME does not allow alternative ports to be used for security reasons, so we'll need a solution for that.
Many ports have also been restricted by the browser because you can format malicious HTTP requests to be an DoS vector for certain services, like IRC, which has been abused by malvertisers in the past. Because of this you'd still be working with a whitelist of ports, only extending the problem a bit longer.
I'm not entirely sure what privacy your NAT guarantees for you. Individual devices can already be fingerprinted by their behaviour, so you'd need to run identical software on identical hardware to combat that. If you manage to do that, you're only one Set-Cookie away from unique identifiers anyway.
Because of the refreshing nature of privacy extensions, you can't derive an exact number of devices active on a network. More and more random new addresses become in use over time to the point where you'd need access to your router (which your ISP already has, unless you configure your own) to get a proper count. You can at best get guesstimations, but that's not much different from the result of NAT.
In theory, I agree with you: pasdive fingerprinting IPv6 is easier than passive fingerprinting IPv4 on an ISP scale or larger. In practice, though, I don't think it matters. Someone who has access to all traffic from your network, probably has access to some kind of boundary as well.
If you already install your own traffic collector to NAT everything through so your ISP modem doesn't see your devices, you can do the exact same for IPv6. NAT may be strongly discouraged, but it's still possible using the same techniques.