@sileo.eth
To answer the initial question (not discussing Tailscale atm), yes you'd have to forward port 22. I recommend using public key authentication and disabling pw auth. Installing fail2ban is also recommended. Additionally, there's a possibility to whitelist specific IPs if you wish.