> You can also use node sharing to invite people you trust to your server. Generate an invite link in the admin panel and they can use that to join your adventure.
Though I did try to find the node sharing link generator in my control panel and failed - maybe it isn't available for non paying customers or maybe I'm just not very good at looking for stuff!
It seems to be in an invite only beta. Maybe the article was scheduled and mistimed?
I wouldn't say mistimed so much as "we were excited to get the post up". Node sharing is indeed in invite-only beta, though we're planning on opening that up very soon. Apologies for any frustration/confusion.
You can set an allowlist of mojang account identifiers in your server.properties.
I don't know how airtight that is, though, and I guess if you're running a public server on the default port 25565, you can expect to receive a bunch of connection attempts from people you don't know that will ultimately be unsuccessful but will take some CPU to reject (just like SSH on port 22).
It's probably less likely to receive UDP traffic on tailscale's default port these days than TCP on 25565. Even then, I would bet that it's cheaper to discard the tailscale/wireguard packets that you don't trust / aren't authenticated than it is for minecraft.jar to either fail to authn a client with mojang's servers or authenticate a client and then see that it's not in the allow list.