Tailscale for embedded devices?

What’s the best way to bridge an embedded host onto a tailnet such that magic dns still resolves it? Consider IP appliances that can’t be modified to run a tailscale client, such as IP video cameras, GPS NTP servers, or a CA (where you want to minimize surface area.)

I see that the answer is probably to configure a tailscale subnet router from a separate device.