I still haven’t found an ideal solution, despite a variety of options.
Cloudflare tunnels are good, but Cloudflare terminates TLS certificates, and scans the traffic. People host on premise for privacy, which is moot if using Cloudflare.
FRP is simple and works, but it takes inbound traffic from open Internet. A vulnerability in it could compromise your environment. The transport encryption is customized (probably using TLS). It’s not a VPN quality software, going through audits. It may need a reverse proxy in front of it.
The ones that make outbound connections seem better. Ngrok pricing is not good, particularly when using custom domains. Tailscale funnel seems to be for short lived lightweight connections, has bandwidth and speed limitations due use of relay servers, kills my CPU, and requires a tailnet.
SSH reverse tunnels require some scripting with autossh or similar to ensure persistent connections.