everything works fine with just tmux + mosh, but I like to bind sshd on the wireguard interface so that there aren't any listening ports accessible from the public internet
yes, but wireguard is undetectable because the server won't reply to packets that fail auth whereas sshd will respond (with a banner!) to anyone who comes knocking
stealth is basically impossible with TCP