OpenVPN, Strongswan, Tinc, Wireguard and even Tor without obfuscation modules and without private entry nodes are all trivial to detect and block. Assuming one can reach a VPS provider outside of the country, the most likely solution would be an HTTPS enabled proxy using SNI and a wildcard cert that makes it look like one is just pushing code to a git repo. HAProxy could peel off the default traffic to an actual Gitea git repo and forward the proxy traffic to a Squid SSL-Bump proxy. Create a VM somewhere, give it a DNS name like "git.yourdomain.tld" and then proxy through that HTTPS connection from a different SNI name like "artifacts.yourdomain.tld". This isn't perfect but may work.
Another option if SSH is still permitted to VPS providers, one could tunnel over SOCKS connections through a VPS VM initially as the first hop, then through a friends home in that same region outside of Iran as the second hop to minimize the number of CATPCHA's one is subjected to. SSH can make multiple hops transparent to the client. Ensure DNS resolution in the browser is set to use the upstream SOCKS connection. As with the previous proposal, try to make the VM look like a git repo or something else work related.
One could find some examples of both of the above ideas on SuperUser, StackExchange and ServerFault.
Here [1] is a previous discussion on the topic or Iran internet lock-down.
[1] - https://news.ycombinator.com/item?id=33025954