In late June, OpenBSD added the new kernel driver
wg(4) for WireGuard connections, eliminating the need for any userland tools to provision and use a WireGuard VPN. This driver is in -current now, and will be included in OpenBSD release 6.8 expected on or about November 1.
I experimented with the new driver, and have now deployed it in (personal) production for use with an existing VPS server as my external endpoint, with both an Android phone and a OpenBSD laptop. As VPNs go, this was extremely easy to deploy.
One additional advantage I did not foresee: since WireGuard will tunnel IPv6 within IPv4 (and vice versa), I can use IPv6 from within IPv4-only LANs -- a common limitation in North America.