Great post, can't agree more.
But instead of relying on Tailscale (US company) I use plain mTLS for securing my services. It's about the same security level, but without active vpn clients drawing energy and without external dependency.
Works really great, can definitely recommend it.
Go EU!