Wireguard on a $15 Raspberry Pi Zero works as well[1], for those who don't have AppleTVs.
1. Or OpenVPN on your router. It's probably to gove yourself a tunnel to your home-network you can use from your phone or laptop from anywhere in the world. Avoid default ports if you can.
The only admin work I ever do is generating a new config when I get or replace a peer device. I imagine this is inescapable even on Tailscale? Are there specific, recurring tasks that you think would cause it to rise to the level of a second job, rather than a once-and-done 5 minute install?
1. Or OpenVPN on your router. It's probably to gove yourself a tunnel to your home-network you can use from your phone or laptop from anywhere in the world. Avoid default ports if you can.