If you fully trust the (encrypted?) authentication mechanism of CTCS, then it's OK to open the port from the internet.
If you don't trust it, use ssh tunnelling only for such purposes, if possible with public key auth only and password auth disabled.