i had a caveat though... the SSH service was coming up before wireguard, and because it was set to bind on the IP address created by the wireguard TUN it was failing to start on reboot
i added
[email protected]
to the end of the After line which has network.target and auditd.service on it in default (ubuntu 20)
and now after i reboot the VPS i can get back on the SSH within half a minute