Previously I used Dehydrated to request certs, but I had to change the setup and found it surprisingly hard to use certbot without it messing up my lovingly handcrafted Nginx configs. This seems to be a sane setup :)
Overlaps somewhat with /c/floss_replacement and /c/privacy; crossposts welcome