Earlier quoted context omitted.
No no, you should totally use separate certificates (for our SaaS that's crucial, otherwise we would let our competitors know who our entire client base is, if all the domains would be included in one certificate) I don't know too much about certbot's nginx plugin, I don't use it and don't see the benefit to be honest, we ran into problems with it (it didn't work for us because our clients have to set up a CNAME DNS…
Thanks for the advice! I'll look at it all on the weekend.
[1] https://wiki.archlinux.org/index.php/Nginx#Managing_server_e...