Earlier quoted context omitted.
This. Configure private vlans and/or Wireguard or whatever VPN software you prefer.
And what about mTLS?
With MTLS, a good security posture is to log every connection establishment, with basic metadata about the certificate involved - it's SAN and public key hash are the best bet. For troubleshooting, do that logging before the authentication decision. But anyone can make their own certificate, so keeping network controls keeps that list free of clutter.