Headscale control plane is not in the data path. That distinction matters. My mesh nodes in Taipei talk direct to nodes in Tokyo and Singapore, no hairpin through Amsterdam. Latency drops 40ms.
wireguard hub-and-spoke vs mesh: my 20-node headache
I am in Lima, my hub is in Miami, my other node is in Santiago. 180ms to talk to my neighbor because everything goes to Florida first. I did not know Headscale exist until this thread. Thank you ronwit, you save me maybe.
Ya see told you mesh is the way dont overthink it just do it
I break things professionally so let me tell you: Headscale ACLs break things professionally. The default is allow-all, you think "I will lock this down later", later never comes, then you have 20 nodes with full mesh to your production database. Ask me how I know.
If it fits in a rack I've racked it, and if it has a control plane I've lost sleep over it. Headscale is fine. Tailscale SaaS is fine. Your own hub-and-spoke with keepalived on two cheap VPS is also fine. The 190 connections thing is a red herring, WireGuard is stateless, the kernel doesn't care.
In Bangalore I pay for bandwidth twice, once to ISP and once because cloud egress is not free. Mesh direct means my Pi in Chennai talks direct to my Pi in Hyderabad, not both via some VPS in Mumbai. This matters for my wallet.