WireGuard doesn't do NAT traversal. That's the main thing this adds. And this also adds a CLI tool + library to do streams over WireGuard w/o installing kernel routings, requiring root, etc.
NAT traversal is a different topic, WG won't help in that, and that can actually be a pain. I guess we should be using IPv6 already, and this tool would be largely redundant already. (not completely, encrypted access to isolated networks is a valid use case)
And hole punching gets a lot simpler when you’re behind NAT since you don’t need any kind of rendezvous server to determine port mappings.
In other words, IPv6 does help substantially—the same hole punching techniques are not needed.
NAT is honestly smaller of an issue and rarely encountered, but it's useful for example to expose services on my laptop to my phone, kind of like ngrok. That can be quite hard on vanilla wireguard.
For me the biggest thing tailscale/netbird solves is still the automatic handling of the peers, acls, or in other words automating fireguard config.
Public/private key pairs are hard? It's no more terrible than other projects that require configs.
Idk? I found it pretty easy to configure by blindly following the tutorials and copy-pasting keys. The only footgun is the keepalive setting, which will screw up the tunnel if one end is behind NAT, that tripped me hard, but besides this, no issues at all.