Remote management of virtualized infrastructure introduces security risk when management services are exposed directly to the public internet. This risk is amplified when testbeds are intended to support sovereign edge computing workloads that require secure, isolated infrastructure. This study designs and evaluates a secure remote management architecture for a Proxmox VE node using a Tailscale overlay network and interface-specific firewall hardening, establishing a foundational infrastructure baseline for sovereign edge computing. The research follows Design Science Research supported by a network engineering evaluation procedure. The artefact was developed through problem identification, topology design, implementation, measurement, and evaluation. Data were collected from Tailscale status checks, Proxmox VE observation, ping latency testing, relay netcheck output, iptables verification, and external port scanning before and after firewall hardening. The Tailscale path achieved an average round-trip time of 0.434 milliseconds with zero packet loss, comparable to the public Internet Protocol path at 0.540 milliseconds with zero packet loss. Before hardening, public scanning detected management ports 22, 2222, and 8006. After applying interface-specific firewall rules, the external scan reported no open ports among the top 1000 ports, while private access to Proxmox VE through the Tailscale interface remained available. The proposed architecture demonstrates that overlay networking must be combined with firewall hardening to remove public management exposure without disrupting authorized remote administration. The result establishes a replicable foundational infrastructure baseline for sovereign edge computing, providing the first stage toward deployment of secure edge computing systems in resource-limited environments.