For anyone interested, I made a very simple WebFinger responder
https://github.com/nikdoof/simple-webfinger
Feed it a OIDC URL and it'll respond back valid responses for Tailscale after adding keys in the 'accounts' dict.
Does the job, very manual twiddling, and at some point i'll get it to read the accounts out of Authentik itself.