I am using it in this exact scenario as well. Unraid lives on my main LAN and any device on my main LAN can hit the containers. Any device on a different subnet is a no go. As a test I made sure nothing was blocked between VLANS with the same issues, explicitly wrote allow rules, tried adding routes etc with no success.
I use a commerical provider that supports port forwarding and run Emby behind that over the tunnel. Absolutley hate having to put the firesticks etc on the main network to be able to access Emby locally.
I wasted most of my day setting up a VPN client on my UDMP, enabling VLANs in Unraid and assigning the containers to a VLAN, just to realize Unifi doesn't support forwarding on the interface. Saw a forum post on modifying the IP tables on the UDMP and tried that, even if it worked, they don't persist after a reboot.
It sounds like you abandoned the built in Unraid wireguard tunnel in favor of a container. Are you able to access your resources properly now?