Feature suggestion: on demand access for mobile clients

On iOS and Android it would be an extremely good battery saving win to be able to configure the clients to be unidirectional. For many setups the wireguard link does not need to be maintained except when the client is making an outbound connection, ie to a network web server or service. Leaving the VPN in an effectively disconnected state would save considerable battery and not have any impact other than a slight delay for the first packet while bringing up the wireguard and tailscale control links. I can’t really accord the 10%+ battery hit leaving tailscale connected, which is disappointing.

