Earlier quoted context omitted.
This is always annoying me with 1Password, before that I just always added subdomains but now I'm usually hosting everything behind Tailscale which makes this problem even worse as the differentiation is only the port.
You can use tailscale services to do this now: https://tailscale.com/docs/features/tailscale-services Then you can access stuff on your tailnet by going to http://service instead of http://ip:port It works well! Only thing missing now is TLS
> tailscale serve --service=svc:web-server --https=443 127.0.0.1:8080
> http://web-server..ts.net:443/ > |-- proxy http://127.0.0.1:8080
> When you use the tailscale serve command with the HTTPS protocol, Tailscale automatically provisions a TLS certificate for your unique tailnet DNS name.
So is the certificate not valid? The 'Limitations' section doesn't mention anything about TLS either:
https://tailscale.com/docs/features/tailscale-services#limit...