Earlier quoted context omitted.
I actually have the reverse model: requesting certs is done by its own isolated and dedicated container and scp’d to the server which needs it. Compromising a web-server will thus not compromise my DNS.
I like the sound of this idea, happen to have a Dockerfile/scripts for it on GitHub?
It’s just a basic setup with dehydrated[1], some bash scripts for deployment and cron though.