Once you get to N = >10 devices, and expect some degree of decentralized communication between them you find yourself maintaining N^2 entries. Every change to the set of public keys, require you updating N entries. Things get worse once you want consistent rules on what-device-should-access-what.
I initially used WireGuard, but as my home lab scaled, it became unwieldy. Some people could work around these limitations with bash scripts, but if you have an heterogeneous environment (esp iOS clients), making programmatic configuration changes to WireGuard becomes trickier.
Today I use Tailscale (with Headscale as the control plane) for all users, and WireGuard as a emergency access to key servers.
Does headscale fully replace the corporate tailscale network? I've been looking at replacing my home wireguard if I can self-host tailscale but haven't had the free time to really figure out how much privacy I can retain by using headscale.
It definitely can. By default it ships with the normal Tailscale DERP map but it also ships with a default-off DERP server. You can turn that on and set your DERP map to only include that one server (or you can fan out a couple if you want). At that point you're not using Tailscale assets at all.
Thanks! Once I have some more time this winter I will take a look at using this to replace my wireguard setup.