The attack you mention is solved in the second part of the article.
I did notice that you tried to mitigate the risk, but why not just pick a high port rather than this complex redirection?
Your scheme is smart and creative but unnecessarily risky.
SSH can do remote listens to the world by itself, no second nginx needed, but sish or ngrok might be a better solution for the general case.
Anytime you punch holes, you're taking a risk, so make it as narrow as you can.
I did notice that you tried to mitigate the risk, but why not just pick a high port rather than this complex redirection?
Your scheme is smart and creative but unnecessarily risky.
SSH can do remote listens to the world by itself, no second nginx needed, but sish or ngrok might be a better solution for the general case.
Anytime you punch holes, you're taking a risk, so make it as narrow as you can.