Thanks I do understand better now.
Always best to keep your node behind your router NAT & firewall.
I was thinking more of a hybrid model; using both headscale and tailscale.
I read/watched someone setup where they self-hosted everything with headscale, then used tailscale as the public IP. It was a interesting/creative setup.
I'll have to find that again and share.
Stoked for next release of raspiblitz with a script for Tailscale