I'd be pleased to be persuaded that I'm making this unnecessarily complicated! I'll experiment with the single-interface approach and see if/where I get into trouble.traffic into its ethernet port is routed over the VPN
How is SSH traffic handled? Both my WGbox and one of the client boxes are headless.