Yeah true, that's part of making wire guard more convenient. You have to have a 3rd connection for that I think. In tailscales case it the headscale server.
Unmapped
From what I understand tailscale is basically wire guard but made convenient. And how they do that is by managing you wire guard keys for you. So I would have assumed they could use the keys to access your network. HOWever while trying to look into this just now I found out tailnet lock exist and it says "When tailnet lock is enabled, even if Tailscale infrastructure is malicious or hacked, attackers can’t send or receive traffic on your tailnet."
Not really directly answering your question here so feel free to ignore me. But if I'm understanding right your setup sounds like a more complicated way of doing what I am.
I put tailscale on all my devices. And in every docker compose for the ports I do. TailscaleIP:hostport:containerport
So nothing can be access on local network at all. Only through tailscale. Which I can access from any of my devices locally or remotely without opening a port. All E2E encrypted I'm pretty sure. The only con is having to trust tailscale.
I do keep Plex port open for friends though.
I think signal servers may be using aws hosting.
I see it a lot when ppl complain about signal, but just can't understand why you would save 10+ years in old msgs. Almost all my signal conversations even GRP chats are set to 1 week auto delete. If something important Is said that I need to save, I copy/paste it into my note app where I can organize it. Its sounds so impractical to dig through 10+ years of data everytime you need something. Plus it would be awful to know there is a log of all the dumb things I said 10 years ago lol.
I don't care about the photos. But glad to hear they are taking photos and music out of the main app and making it less bloated.
Hotkeys are almost always faster than using a mouse. Ctrl + tab & Ctrl + shift+ tab. Also alt + 1-8.
Ctrl + T to make new tab and Ctrl + W to close current tab.
Stock iOS may be better for privacy than google on a OS level. But so many of the best Foss and open source app alternatives are android only. Like iOS can't even run real Firefox. Much less things like newpipe.
Well Plex has the live TV stuff you just need a tuner. So there are programs that act as tuners for IPTV. Like a middle man between IPTV and Plex. I'm still switching around trying to find one that works best. They all seem to have pros and cons. There is Xteve and Telly. Xteve is easier to setup but hasn't been updated in a long time. There is a newer fork of xteve called Threadfin but it has a bug which keeps me from being able to add a m3u link. But I found a fork of the fork where the bug is fixed.
From what I understand running high bandwidth things like video streaming through cloudflare tunnels will get your cloudflare account banned or charged (which is why they require payment info to setup tunnels).
Best to keep things like emby, jellyfin, and Plex to tailscale or just open the port.
Idk how emby works but with Plex I feel pretty safe having port open. Since any logins have to auth though Plex's servers.