@jerry my answer would be : Damn too many.

It’s why i quite like tailscale ACL that actually allow to write test, so the ACL changes are ignored if the ACL fail the test.

You are not directly link to internet and it’s also preventing accidental opening to any people you may have invited with those ACL test.