By making technologies available only in a "secure context", they're blocking them out of this whole category of use cases.
For the permanent installation case, it's typically easier to use mDNS domains since they're shorter. 'mediapc.local' is easier for guests to type than 'mediapc.local.mort.coffee' or whatever I'd end up with.
What would be a good solution is self-signed certificates, but that too is a non-option until all browser vendors downgrade the warning from a "Someone is trying to hack you!" style scare screen to a more informative "this is a self signed certificate, do you trust it?" style warning screen.
Gee thanks corporate overlords, whatever would we do without your cloying efforts to provide quote-unquote-"security"?