I run split horizon DNS[0] (As I manage both my internal and external DNS zones), which works just fine.
For external-facing services, I use Let's Encrypt (LE) certs and when internal services run on the same hosts, I use those LE certs for TLS/HTTPS.
For internal only services, where encryption is desired, I use self-signed certs. That said, in many cases, since the internal services don't actually have any data that needs data privacy across my internal network (e.g., Podgrab[1], Deluge-web[2], etc.), often I don't bother.
I'm not sure (but I probably would) if I'd go that way in setting this up in 2022 (the origins of this set up go back to the 20th century), but it works for me and as it's already set up, there isn't much to do except maintain and update the zones/certs.
It's not that hard or that big a deal, IMHO.
[0] https://en.wikipedia.org/wiki/Split-horizon_DNS
[1] https://github.com/akhilrex/podgrab
[2] https://github.com/MAESTROHANTER/deluge-web
Edit: Added missing references.