I attempted this on a VM inside a Linux host and got a lower privileged user from inside the guest VM to ssh to a root-privileged user outside on the host.
Both were authenticated to Tailscale with the same gmail account, so from an OAuth perspective, this is valid.
From the OS perspective though, the host SSH port is blocked, and a guest should never get full root access to the host or see the host's resources.
I am not sure if I am confused about something, or maybe there are prod use-cases where the same IDP identity should have different roles/privileges depending on the machine, and Tailscale SSH breaks that?
You might want to try the Pixel Slate as a iPad Pro replacement as that would fix most of your issues. Several folks report doing this here: https://www.reddit.com/r/pixel_slate
Not a book, but if you are looking for a real-world motivation for a lua project - try out awesomewm, a window manager thats customizable using lua. You'll write some lua scripts and end up with a workspace to your liking.
Most orthodontists will say anything except water is a no-no - coffee and tea will stain your aligners, and they almost always permeate the aligners into your teeth, causing decay until the next brushing. Juice is even more harmful with the sugar and fibre. Also, hot beverages can deform the aligners.
I know cases of people who tried having drinks with straws, and realized it wasn't a viable solution. The drink still ends up permeating the aligners.
Read in a book: "If you spoke to your friends like you speak to yourself, would anyone ever want to be your friend?" ("Living with a heart wide open").
The line instantly changed my self-talk from negative and dystopian to compassionate and constructive i.e. things like scolding myself when I missed a freeway exit while driving. Turns out my case is not uncommon - most people call themselves stupid 8-10 times a day.
I am not sure if I am confused about something, or maybe there are prod use-cases where the same IDP identity should have different roles/privileges depending on the machine, and Tailscale SSH breaks that?