Hello Alexander Redmann
Welcome to Microsoft Q&A Platform, thanks for posting your query here.
PrivateLink is just a egress to the API server. The Egress only happens through the options you defined already.
With Egress, you would need the egress taking care of SNAT, which the PE will not do and other things (I could think of only SNAT at the moment).
For egress, could you check this https://github.com/Azure/kube-egress-gateway
https://learn.microsoft.com/en-us/azure/aks/egress-outboundtype
I checked with internal team on this and team is working on the managed solution for this project, and it could be deployed into AKS cluster already before that.
Hope this helps.