fd00:192:168:136::1 up through fd00:192:168:136::4
WireGuard on the VPSs will only accept IPv6 packets with source addresses which you added to the allowed IPs there.
I've seen some discussions about advertising both a PD and a ULA address to the LAN. Might be worth looking into this.
That's exactly how it's done, yes. Though I'm a bit surprised you had to advertise a route to the remote ULA subnet via RAs. As long as OPNsense is the default gateway, this shouldn't be required, right?