Another option is to use a DNS Challenge and just copy the cert and privkey files to your web server. The DNS Challenge could be run from any machine. To automate requires your DNS provider to support an API. See the acme.sh github for all the DNS providers it supports (which is many). A manual method is possible but tedious every 60 days so best avoided.
This would allow you to keep acme.sh itself current and the two cert files are pretty small especially with the current default shorter chain.