However, if you use pubkey and not password authentication, is there still any real risk? If I post to the public internet "my <hostname> is listening on port 22" and it's pubkey auth only, is anyone ever going to get in even if I allow unlimited bruteforce attempts? You'll have to steal my laptop to get the key, by which point you have my Wireguard config and keys as well.
Not at all to say defense in depth isn't worthwhile, of course it is, but I don't think ssh with pubkey is inherently vulnerable.
I use Wireguard and already implement the suggested topology. Just food for thought.