These days I use Tailscale for my home setup, which is similarly awesome. Both obviously have closed source components. I was convinced because (1) you can operate a Tailscale network entirely on OAuth2 with an external identity provider, no long-lived API tokens and less for them to mess up; (2) it runs over Wireguard and I like not having to trust more people on the crypto. I had been trying to basically build a mini-Tailscale when I discovered it already existed. Others in this thread have mentioned being able to operate your own control plane nodes for it, I'll have to look into that.
The primary difference between them is that ZeroTier is layer 2-ish whereas Tailscale is layer 3-ish. Ironically enough, ZT's design is more oriented towards scalability, whereas Tailscale is more of a fully connected graph with independent encryption on each edge. ZT rules are like configuring `pf` on your whole network at once. I miss that, especially the capabilities system. With Tailscale, if I were doing more than my own machines, I would probably rely on actual firewalls rather than their miniature JSON one. But the DNS features on tailscale are unmatched. You get `ssh myothermachine` with zero configuration. That's hard to beat at home.
I cannot recommend highly enough giving one of these a go. They make the internet fun again.