How do these large SaaS applications use letsencrypt to generate tens of thousands of certs?

I’m not sure I follow you.

If for example on heroku I add my custom domain bluebikes.com, they will issue a lets-encrypt cert for bluebikes.com. What does the 2 PSL heroku domains herokuapp or herokussl have to do with this?