My endpoint is a pretty stable (though technically dynamic) IPv4 on one end, but the other might be a cell phone with CGNAT, some random WiFi, blah blah etc. TS does that. If you don't want to use it, cool. Don't. I'm willing to make the tradeoffs to use TS for now. That could change in the future.
No but hole punching isn't really needed in that scenario. Open a port on the IPv4 side + dyanmic DNS. More than likely that is what tailscale is doing for you. Opening a port on that end w/UPnP. But can't argue with how simple it is with tailscale.