More than that. They're saying that they're running a userspace implementation of both the tcp/ip stack and wireguard. Your machine isn't a peer to the wireguard tunnel, only flyctl is.
Of course, your machine can be a peer also. You can create peers to your organization with `flyctl wireguard create`.
But that isn’t the case for all of the other uses of flyctl.
You can’t make connections with other processes over the same connection flyctl makes when it’s doing stuff.