I think such setups are at least as secure as having tailscale in front of it and they are web standards conform. I dont need a client app like tailscale, I can just use my normal browser and internet conn.
I always make sure envoy/all other apps are on the latest security patcb anyways.
I probably won't allow everything through it (eg: postgres, clickhouse etc can stay on tailscale), but I've been stumbling into use cases where I want to share things with friends or colleagues, and I don't want to put them on my tailnet.
What all user-facing software should have is a minimal-overhead connection option to improve performance inside user's tunnel of choice.
Pure QUIC gets blocked easily, SSH requires wrapping, even Tailscale mimicry is basic and they still ignore simple protocol improvements available.
basically an embedded tailscale.
> The public relays we run have seen more than 200 million endpoints created, in the last 30 days alone
Please just make it work seamlessly with my existing SSH credentials. Like SFTP.
But yeah, you could also make use of your ed25519 ssh public key as client certificate and accept based on fingerprint like ssh
Nothing prevents RustDesk from implementing TLS TOFU (see e.g. Gemini Protocol), which offers the same security guarantees as SSH TOFU.