Which Should You Choose?
WireGuard directly — Full control, simple site-to-site, technical users
Pangolin — Expose services publicly, homelab, reverse proxy use case
Tailscale — Easiest setup, don't mind some vendor dependency
Tailscale + Headscale — Tailscale UX with self-hosted control plane
Netbird — Full FLOSS, mesh VPN + reverse proxy, organization with SSO needs