Comment by mbesto
I use CF tunnels pretty extensively with my home unraid server.
The TL;DR is this - there are certain apps I host that I want to be public and don't want to onboard a Tailscale node (for example my sister uses my Plex server). So, instead of setting up a reverse proxy, I simply create a subdomain in DNS (via CF) and then route that subdomain to the CF tunnel.
It's like 3 form entries to do all of this for one site/service and automatically creates an SSL cert for me. I love it.
Out of curiosity why not give your sister restricted access to your tailnet instead? Then nothing is public.