tldr make sure the bastion box can reach the stuff you need it to reach as far as subnets and security groups go, ensure kernel will fwd traffic from WireGuard clients, run WireGuard daemon, and expose it to the outside world via eip. I’m oversimplifying (dns, sec groups, routing client traffic to other subnets) - but hopefully that explains the gist.
I have a small Python script that takes a XLSX file as input and populates a dir with config files and QR code images for each user.
Or you can check out some of the OSS ways to do self-service vpn mgmt with a web UI that authenticates against Google auth. I haven’t deployed this yet but it looks cool https://github.com/subspacecloud/subspace
If you know this sort of tech well it is not hard to deploy and manage yourself. But tailscale has a really killer clientside experience and “just works” so honestly it might be worth the $$$
It's not unlike Tailscale and nebula (that others already mentioned) but I think it deserves to be mentioned.
At some point you’ll probably want to integrate with some identity management , but dozens of users and hundreds of servers are totally fine to manage as yaml in ansible IME.
You can bolt-on SSO fairly easily - just create a certificate signing service. I created https://github.com/unreality/nebula-mesh-admin in a weekend, so its fairly easy to add a SSO flow in.