Current status: reverse engineering my hacks to this test machine so I can write up proper install instructions for a slightly more proper version of it. Also, mutating the hacks in the process, because why not improve them while I'm at it?
Achievement unlocked: first NAT setup with nftables instead of iptables, for no really good reason.