Thechnically speaking, content on FIPS doesn’t need TLS because it’s encrypted already.
But yeah, applications like browsers often assume that all IP traffic is unencrypted and require TLS regardless.
I think self-signed certs is the less invasive workaround, unfortunately.