I had some difficulty with a setup that involved both vpn client and vpn server. The official tutorial from opnsense for the vpn server was quite different from what the wizard did, and that caused some confusion. There was no documentation on the client side, but PIA was helpful with the details missing on the pfsense documentation. Maybe the wizard would have eventually worked.
I like your point about unbound + pihole. I will.definitely try to set that up.
You are also right about moving trust from A to B. However, I was certain I could not trust A. Also, some of my machinnes can hop to another tunnel, to mix up the traffic more.
I have also struggled with a good wireless setup. Mine is currently cobbled together from decent commercial routers that have been tweaked to just pass though, a couple with dd-wrt. The radios are good, and most of the processing has been moved to my firewall, so it works, but... I even tried a more expensive mesh setup, but it did not give me the control I needed, and was not much speed improvement anyway, so returned it. I would like to hear of a good, not-too-expensive alternative, so will be interested to hear if you pull the trigger on the Arubas.
We actually have access to fiber but, am waiting on that. It will get cheaper eventually, and it is always nice to have a significant improvement to look forward to.