

1·
17 hours ago@dave rudimentary split dns. All my FQDN are using a compliant example.com my network serves those app.example.com, my AdGuard does rewrites for them and in the public space i A DNS to them using Tailscale IP.
May not be approved by enterprise architects but works with no public port openings

@dave I see. I am not experienced in Kubernetes so cannot help there, but what you could do, is having a public reverse proxy and your public dns entries resolve to that ip, then caddy will serve the public side https://prozak.org/007-setting-up-vps-webproxy-to-homelab-servers-using-tailscale something like this I think can help