That's it. No certificates, no certificate authorities, no HMAC negotiation. Just Curve25519 key pairs and ChaCha20-Poly1305 encryption.
Surely an actual human has written an article like this that you could share instead.
I enjoyed this blog post about how Tailscale does NAT traversal, which covers the second half of your linked article: https://tailscale.com/blog/how-nat-traversal-works