supporting 400+ laptops from previously tech-illiterate users in the field. we tried everything for remote patching and fixing things and nothing worked universally. that includes stuff shipped with them (ssh, Gnome and Plasma RDP, VNC, etc) and 3rd party FOSS things. wireguard-ing all them laptops for remote access introduces buncha complications at this scale.
only thing that works: bring it to the "shop", ansible script to exfil home subvolume, install fresh ubuntu (working on replacing that with debian), patch snap and bunch of other annoyances, restore /home.
seeing as how you only got grams and co. to take care of, wireguard + ssh is the only low-overhead, works-most-of-the-time solution.
