This. Wireguard is a single short text file with keys. It's simple and robust, and setting it up on a client like a laptop or a phone is equally easy. Tailscale or Headscale (the self-hosted version) are massively overengineered for something as basic as accessing your Linux ISOs from your phone.

I'll argue though that the convenience and autonomic management make a big difference in that case because if your Wireguard configuration is busted you might need a working Wireguard to log into your homelab and fix it.

Of course the default behavior that Tailscale forces you to reauthenticate periodically can cause the same problem unless... you turn it off. You know things like that always happen at the worst time.

It’s also entirely impossible to use by itself when both devices you’re trying to connect are behind a NAT or some other restricted network.

That's true, but the $5 VPS should have a public IP, either v4 or v6. Other devices can route their traffic through it, and then every device can reach other devices, regardless of NAT.

It better have v4 if you ever want to use it while traveling. v6 is still not widely enough available on public Wi-Fi networks and even many mobile operators.

On some OSes you could probably also use some additional 4->6 tunnel, but that probably doesn't work stacked under Wireguard on iOS and Android.

But I'd think at that point there'd be arguments for using that vps to instead facilitate a p2p connection... right?

Yes, but only if the VPS becomes a bottleneck. Otherwise self-hosting Headscale does not seem worth it. My guess is that the threshold is at dozens of devices in simultaneous use.