Below is my current understanding of the mpf infrastructure in terms of network connections required.

In some cluster configurations, the TCP connections from the machines to the ipyparallel controller can be hard to achieve. mpf could leverage WireGuard tunnels to achieve this connectivity when starting the ipyparallel cluster. The tunnel endpoint could be on the controller when TCP connections are not possible or likely to be interrupted, or on a third-party node.
I would rather like to rely on a tool doing such auto-deployments through SSH than develop our own.