Does revoking org access from a team member invalidate their wireguard configs?

If we remove org members, do their wireguard tunnels remain accessible?

Yes. The wireguard tunnels remain accessible as they exist on the org level, not the user level.

How can I remove the wireguard tunnels of developers who no longer have access?

You can use fly wg list to find the wireguard peers you want to remove and fly wg remove to remove them.