I think you've got it. Tailscale
is installing WireGuard. You have to have privileges to install Tailscale. They can tell the OS to route packets through their virtual interface.
We could too! This is all in `wireguard-go`. But we'd have to prompt users to escalate privileges every time they tried to SSH somewhere (or, worse, install a long-term resident thingy, just to SSH to things). We don't want to own your VPN connections!
This is an end-run around all of that; we just take responsibility for all of TCP/IP, in our dumb little command line program.