Site-to-Site + PBR with one end behind NAT

There was a similar topic recently:
Reverse WireGuard tunnel
It was resolved using custom routing tables.

I documented the critical steps here:
Route VPN server LAN via VPN client