You can run this entire first section with ryansch/openvpn:latest on a more powerful machine than the pi.
OVPN_DATA="ovpn-data"
docker run -v $OVPN_DATA:/etc/openvpn --rm ryansch/openvpn:latest ovpn_genconfig -d -N -b -C AES-256-CBC -T TLS-DHE-RSA-WITH-AES-256-GCM-SHA384 -a SHA512 -n 192.168.8.1 -p 'route 192.168.8.0 255.255.255.0' -u udp://<OPENVPN_HOST>
-e 'topology subnet' -p 'dhcp-option DOMAIN <LAN_DOMAIN>
' -E 'remote <OPENVPN_HOST>
443 tcp'
docker run -v $OVPN_DATA:/etc/openvpn --rm -it -e EASYRSA_KEY_SIZE=4096 ryansch/openvpn:latest ovpn_initpki