Honestly i feel like i would trust a custom application for this more than random hardware.
Something like Cloudflares warp bit for this where the hoster approves what you get access to.
Warp is(probably) boringtun <-> smoltcp <-> pingora.
Edit. As many have said pirating is easier.
And the application would have to allow list IPs and tls retermination too since sni could be forged.
Well it could be fine with sni validation and target IP filtering, but I still don’t like the idea