Will list a few approaches here
1. Use Zerotier instead of Tailsacle since it's just a matter of the relatives joining the network string through their client devices instead of the usual Google auth/SSO.
2. You can setup a VPS on nearest cloud provider and port forward only the 8089 port...