I have a private CA for all internal hosts. It's a bit of a pain to run, but it's neccessary because "internal" includes VMs that run colocated servers and many services to mutual authentication. It's hyper annoying that it's barely to not possible to include our own CA into mobile Browsers so that they can use internal websites. The alternative would be to depend on LE where neccessary, but this introduces an extern…
Also, it may be possible to sign an SSL certificate with two authorities.