Please don't configure your web servers or Docker containers to auto-issue on startup. You should keep a cache of private keys and recently issued certificates, and reissue only if they are out of date.
This is partly to make sure you use Let's Encrypt's resources most efficiently, but mainly it's good for the uptime and deployability of your service. If Let's Encrypt has an outage at the same time you are deploying your site, you don't want to be prevented from completing your deploy. And even if there is no outage, Let's Encrypt may be slow to issue, delaying your deploy.
I agree the current rate limits are tough to work with. We're working on ways to tweak them to fit common cases better, but they will take some time to implement. Very much appreciate your patience!