I think most up-to-date OpenWrt routers can do later (with normal, unencrypted DNS requests), see https://openwrt.org/docs/guide-user/firewall/fw3_configurations/intercept_dns.
The model you mentioned (Flint 2) is supported by OpenWrt.
Pick one of the address between 000000.xyz to 999999999.xyz they are sold and renewed at dirt cheap prices.
Tailscale server can also be self-hosted, look into headscale.
From my own experience, I still can’t setup headscale on my Android phone, I think latest tailscale APP fucked up setting custom server function. Don’t install from Google Play
Also recommend https://lowendspirit.com/
AFAIK LET do shenanigans like requiring service providers to pay to create post there now.
Phoronix article: Coreboot Lands Support For The MSI PRO Z790-P Motherboards
On Dasharo (who worked on support for MSI boards) has pre-flashed motherboard for sale on their website, but looking at the price it’s expensive, but it comes with some support.
I think that means the access point can only run at up to 80Mhz bandwidth, so not full bandwidth.