Okay, it basically works!
One very annoying coda to this, though, is that the "allow internet access" toggle on a VLAN in Unifi apparently *also* means "allow access from the secret, hidden VLAN created by VPN client configurations" too. For this particular use-case it's fine (all these machines already have internet access) but I'd be pretty annoyed if I wanted proper perimeter security around an internal service