Rebuilding Remote Access

The old OpenVPN setup wasn't broken — it was a pile of per-user certificates and a manual onboarding ritual. Here's the case for replacing it with a self-hosted WireGuard mesh tied to our identity provider, and the one rule that makes the swap safe.