Earlier quoted context omitted.
Sounds like you’re doing it wrong. I don’t know about this native support, but I’d be very surprised if it was worse than the old way, which could just have Certbot put files in a path NGINX was already serving (webroot method), and then when new certificates are done send a signal for NGINX to reload its config. There should never be any downtime.
Certbot has a "standalone" mode that occupies port 80 and serves /.well-known/ by itself. Whoever first recommended using that mode in anything other than some sort of emergency situation needs to be given a firm kick in the butt. Certbot also has a mode that mangles your apache or nginx config files in an attempt to wire up certificates to your virtual hosts. Whoever wrote the nginx integration also needs a butt kic…
It is not as if they couldn't already choose (to buy) such short lifetimes already.
Authoritarianism at its finest.