Remote administration normally costs you one of two things: a management port published to the internet, or a hosted control plane whose terms can change under you. And the networks you have to work from — hotel Wi-Fi, mobile CGNAT, corporate proxies — fight the tunnel either way.
What I did
Built an estate administered entirely over an encrypted overlay with no management port published anywhere: a self-hosted control plane, one subnet router into the LAN, split-horizon DNS so internal names resolve to internal addresses inside the tunnel, and a connection ladder that tries direct, then a router port mapping, then a relay.
The result
Every host reachable by name from anywhere, nothing administrable from the public internet, and no third party able to change the terms. The write-up names the load-bearing component too — the single subnet router — because a design review that hides its own weak point isn't a review.