The concern I have with these types of solutions (meaning Tailscale, Firezone, etc.), is that I need to trust the provider not to mess up or maliciously exchange keys with rouge devices. Is this the case with Firezone as well? I see that tailscale addresses this now somewhat: https://tailscale.com/kb/1226/tailnet-lock
(I can't find this idea in the issue tracker and I don't think it's on the roadmap yet, but we've discussed it.)
Unfortunately there is a big convenience-security tradeoff, managing your own keys and certs is a lot of work.