There’s unfortunately no always-on host supporting Tailscale. The Apple TV suggestion in the other comment is pretty good though, since it’s easy for anyone to use. Naturally requires having one though.

I still do not understand. You run tailguard in docker, so the host is surely capable of running tailscale. I must be missing something.

Yes, the docker container is running outside the network