An alternative way to hide your SSH server from portscanners is to put it inside a WireGuard VPN.
replies(1):
I am concerned however about the tedious trend of cramming absolutely everything into HTTP. DNS-over-HTTP is already very dumb, and I'm quite sure SSH-over-HTTP is not something I'm going to be interested in at all.