Tailscale is a bit much for a personal VPN. Just a wireguard server is all most people need. I have a wireguard server on one raspberry pi. My cell phone and laptop have wireguard certs to connect. I also have a travel router that can connect to that wireguard server.
But yeah if you want to share with friends a https endpoint is a better solution.
In my experience, podman isn't really there yet.
Doesn't work as well with docker compose.