

(I don’t need strong censorship resistance; it just has to work in offices and hotel WiFis.
Wireguard on 443 or OpenVPN + Stunnel on 443
Wireguard is easier to setup because there’s no OpenVPN app that packages stunnel (afaik), so you have to run 2 apps on your phone to make it work.
A server like caddy can also accept HTTPS traffic for some regular websites next to the VPN server.
Wireguard uses UDP, so just run whatever you want on 443 TCP with caddy (unless you want QUIC for some reason?)
Anything beyond that and you’d be looking at using a proper obfuscation solution like Shadowsocks or obfs4, in which case you should look into Amnezia or Tor bridges.



The fact that CachyOS more or less successfully replaced Manjaro’s purpose I guess is evidence of Manjaro’s issues.
I forgot but I think Bazzite had similar complaints (due to its use of silverblue) in which case it was just more straightforward to use Fedora or OpenSUSE if you don’t want to work with the read only root system.
Downstream distros need to bring additional value to the table to be worth using, otherwise there’s really no need if you can make a package group that accomplishes the same thing in one go.