Excuse my snark, but not everyone has a static v6 IP. I don't.
>One time setup on the server
Unless you happen to be behind a CGNAT or you're on a mobile network or or or or...
>Installed just like any other distro package, plus one-time setup to generate the key and import it and the server's public key into systemd-networkd / NetworkManager.
And if that won't work you're gonna be stuck debugging the network setup. I certainly do always end up debugging the VPN network stack eventually.
>You generate a key on each device and register the public key with the server. There's literally nothing else to it.
This won't scale to more than like 5 devices without being a major work item if a key was compromised or needs to be rotated (what if it turns out the RNG device was bad on your kernel at the time? Happened to SSH Keys on RPi's).
>I set it up about two years ago and it's been working unchanged since.
Not everyone is that lucky.