Rather than serving the content API on a high port, use a subdomain like content.{{ domain }}. This'll be friendlier to the VPN.
We'll have to transition over gracefully to avoid breaking everyone's builds. This'll be easier once more builds are hosted in Strider.