we need to re-think port forwarding for this reason. Basically we stick ssh in there so that you can ssh to the host over the wireguard interface. But this breaks ssh'ing over the ingress gateway bc it captures all ssh traffic and re-routes it to the host