I had the hardest time with this. What I ended up doing instead was provisioning a dedicated vm to run as a tailscale subnet router, then just advertise my gateway and the applicable container IPs via /32 CIDRs. Tailscale will let you do multiple comma separated IPs when advertising routes, so it’s easy to append a new service via IP.
This is why “sure” or “yes” are not part of my IT vocabulary. “Should” is king. “We should be be able to do” or “that should work.”
In the idiocy of stakeholders that want IT to be a magic wand to fix their ineptitude instead of a helpful contributor to their well thought out process, you have to coach everything in the polite “no” that is “maybe” or “should.”