How to get Lets encrypt certificate for Virtual/Cluster IP address

Yes, All the nodes in the setup don't have publicly routable IP addresses. All the servers are within private network.

Also the back end web application nodes running on NGINX are actually load balancer for multiple superset web applications.

Client ----> FQDN of web server(NGINX) cluster -> Two NGINX load balancers -> Multiple superset applications

NGINX-features_High-Availability

But my setup of two NGINX load balancers nodes are on active-passive.