1. Put WireGuard on a Pi. Create a server config.
2. Open the WireGuard port to the Internet (don't worry, it's invisible)
3. Install WireGuard elsewhere, and generate a client config.
All devices can now talk to each other. Tailscale has a "magic DNS" feature, which is nice, but WireGuard also supports custom DNS in the config.
If that‘s you, you probably don‘t need Tailscale.
But if your scenario is e.g. SSHing from your phone to a Raspberry PI behind a carrier-grade NAT, it‘s definitely worth a look.
Thanks. Can you elaborate on how it's invisible? I was looking at the docs and it looks like it defaults to UDP port 51820. Certainly that's visible no?
Not quite the same. Opening a Wireguard port to the Internet doesn't help if the port is unreachable due to weird NATting.
My home ISP puts me on CGNAT so I have no IPv4 access to my network. If I'm out and on a v4-only network, I can't connect to that Wireguard instance without going through other hoops (like a "bastion" Wireguard peer on a dual-stack host, for instance). With Tailscale, it Just Works.
I admit I wasn't able to understand most of those explanations so I could be wrong. :)
[0] https://tailscale.com/blog/how-nat-traversal-works/
[1] https://tailscale.com/blog/how-tailscale-works/#encrypted-re... under "Encrypted TCP relays (DERP)"