It’s possible that Tailscale (SaaS) or Headscale (completely oss and self-hosted) work for you. This is a vpn based on the wireguard protocol with additional magic. While TS will always attempt to create a wireguard tunnel over udp, it can fall back to HTTPS if otherwise the connection cannot be established. If your motivation is to work from a network where only TLS is permitted this could do.
Tailscale has an Android client. GUI.

























Überrascht, dass die Machine überhaupt Ryanair gehört. Hätte gedacht, die sind bestimmt geleast.