

Check out Netdata
Check out Netdata
I don’t know the details of the DMA, it’s definitely possible to provide code-signing to developers that does not go through the app store.
As far as I know iPhones have never allowed unsigned code to run.
Take a look at the nix package manager. It is a very large and up-to-date package repo.
Yes, you can run Tailscale in a container. You could create a second VLAN, attach it to your hosts interface, add a macvlan docker interface to the container and put it directly on your network.
If you have concerns about the software running on your host I would recommend getting a dedicated piece of hardware instead (rpi, zimaboard, etc).
How paranoid are you wanting to be? You can either go Headscale, or Tailnet Lock (my preference) to give your self some peace of mind. It completely depends on your threat model, which you didn’t mention.