You can manually disable key expiration for hosts in Tailscale, and I think you can do it with tags too...
https://tailscale.com/kb/1028/key-expiry#disabling-key-expir...
https://tailscale.com/kb/1028/key-expiry#disabling-key-expir...
I don’t understand how they can have such a strategy, and then not having any decent way to programmatically allocate new keys.
This can all be automated using e.g. the Terraform Tailscale provider, which takes the OAuth id/secret and can then issue keys as needed for the infrastructure you are deploying.