With Tailscale LoadBalancer, TLS is not actually terminated at the edge. The Tailscale proxy does TCP passthrough, so Rancher must serve its own TLS certs. Setting tls: external caused Rancher to listen HTTP-only, which broke HTTPS access through Tailscale.