just use wireguard; tailscale is just the SSO enterprise overlay with a pricing tab.

Wireguard is great for a point-to-point or multipoint VPN set up by a competent network administrator between machines with static addresses. But that's the only thing it does. It does not handle authentication or mobility very well.

git : github :: wireguard : tailscale

No, it’s not. It handles the keys, provisioning, DNS, NAT traversal, and a bunch of other stuff. WireGuard is a great technology - Tailscale is like a usability layer on top of it.

I pay Tailscale nothing, why switch?

I think an important feature for homelabs is NAT traversal