I think it would be great to add TailScale as an app on this service.
tailscale would be very helpful to avoid port opening etc.
Tailscale as other VPN option would be great
Trying to understand how Tailscale is different to Wireguard. Can anybody elaborate to help us understand your usecases and see what the options can be?

Hi David,
my idea is to consume cloudboxes apps from my local network via Tailscale instead of using VPN.
Basic principle is to establish Tailscale tunnel (which is a WireGuard tunnel with additional options) between my device and app/host in CB environment. I could then access other apps if those are running at same host as TS client on your side or enable the Subnet router on that host - https://tailscale.com/kb/1019/subnets
The other possibility might be to configure host on your side as TS Exit node and access apps that way - https://tailscale.com/kb/1103/exit-nodes.
Regarding tun device setup, I’ve seen this could be an issue - https://forum.tailscale.com/t/unable-to-start-tailscale-on-ubuntu-20-04/4585/3. There is a way to use Tailscale without granting /dev/tun access but again, I’m not sure if this could be done in this your environment - https://tailscale.com/kb/1112/userspace-networking