https://fly.io/blog/ssh-and-user-mode-ip-wireguard/

Quote:

> And, long story short, we now have an implementation of certificate-based SSH, running over gVisor user-mode TCP/IP, running over userland wireguard-go, built into flyctl.

Also:

https://fly.io/blog/our-user-mode-wireguard-year/

https://fly.io/blog/jit-wireguard-peers/

This is another one of those things where the graph of our happiness about a technical decision is sinusoidal. :)