There are exactly 0 reason why the private relay couldn't be routed within the VPN or vice versa. There's exactly 0 reasons to make the private relay traffic circumvent the firewall.
>There are exactly 0 reason why the private relay couldn't be routed within the VPN or vice versa.
You don't know that for sure, unless you know exactly how the Apple side of PR works, there could well be circumstances where that would cause problems. At the scale Apple operates at they must come across all sorts of weird an unusual configuration combinations.
There are 0 reasons for enabling private relay and also configuring a VPN, yet that's what the user did. In any case this is documented and Apple provides instructions how to block it.
The issue here is thinking that the VPN subsystem and firewall subsystem and how they work are the product from Apple's point of view. They're not, they're just implementation details. For Apple the intended high level user experience is the product, in this case the UX of the private relay service. If they need to bypass some subsystem to achieve a better more consistent high level user experience then that's what they will do.