What you’ve described is a pain in the ass from a setup perspective. I think what you were trying to say is “be careful about jellyfin vulnerabilities”, but that’s definitely not what came out.
In my situation at home, port forwarding is stupid-simple and just works.
My ISP does not saddle me with CGNAT (or any other form of NAT). I don't use UPnP.
I have a real (dynamic, but just-for-me and almost never changing) IPv4 address to use, and I simply use it.
It works predictably. It works reliably. It is not even a little bit flaky. There is no voodoo involved.
And it doesn't require me to teach my elderly mother how to use Tailscale with her Roku STB.
(I recognize that others may have different situations. But the existence of different situations doesn't mean that one must declare a particular solution to be the "best", does it? KISS.)
E.g. lego supports many different dns providers
https://go-acme.github.io/lego/
And then internally inside of tailscale you could have your own dns server, which serves subdomains of your domain, and for all subdomains you can use the same wildcard certificate.
This also does not 'expose' your subdomains on Certificate Transparency logs
Otherwise you could use solutions like AdGuard Home or PiHole, which both have a Web Interface for configuration, and the ability to block ads and tracking domains.
Note that I don't use Tailscale myself, so I don't know if Tailscale 'needs' something else. But I use pure wireguard, and all of the services mentioned above work with 'pure wireguard'.