Avoid using weak encryption.
Goodbye keyboards and monitors!
Use autossh and a systemd service…
No need to enable full login shell if the only intended usage is proxying.
No need to enable full login shell if the only intended usage is tunneling.