I disagree. You lose out on granular permissions and magicdns.
I run a tailscale instance per service, even if the services are colocated in the same VM. This lets me take advantage of tailscale serve, and I can also move services between VMs without changing access or dns.