Yeah, what @anamethatisnt@lemmy.world suggested is definitely the easiest thing and super practical - I got family members on my tailnet for this purpose. I am however now also looking into some kind of tunneled, reverse proxied and authenticated way to expose a few of my services to other friends where I don't want to have to put them on tailscale or potentially expose them to more than needed via that route.
I haven't started yet, but I am updating my network set up soon to install a dedicated OPNsense router as the edge for my network. From there, the plan is to have a cloudflare tunnel that accesses some of these services via a caddy reverse proxy, with Authelia for authentication. That's the part I have studied enough to feel confident I can do. I am a little weaker on the networking aspects of this, which is where I need to study some more - like isolating those services that are exposed in my network, while still giving them access to some other needed resources within it, etc.
Ooooh that looks interesting. I haven't messed around much with tailscale since I set it up a few years back and hadn't noticed this. Funny, I was just the other day wondering if they might have something like that, but didn't look it up. Thanks!