Automating issuance with Kubernetes

there first needs to be a safe way to pay for things online for that to be a reasonable option

for me its not about the price, its about not wanting to use risky payment methods like credit cards
(which were never a safe way to pay for things even offline) and wanting to avoid what appears to be an increasing risk of censorship in the face of increasingly ridiculous behaviour in web browsers.

especiallly for that first certificate when its testing the waters of trust

automating any of it here is not really option right now - there are multiple domains on the same server and its not some off-the-shelf preconfigured platform and any tools used for renewals would require quite a lot of trust and I cannot take the risk of users being blocked from any public page on any domain here via ordinary http.
I would need to fully understand the process before attempting to automate any of it.

I won’t break what users are using now on any of those domains just to enable tls on one of them

that first one would be testing the waters …

all or nothing was NEVER an option for anything that looks so risky.