Solution to the ssl grief: just get one from the domain registrar, wire it into the k8s thing, boom.
no, it's not automatic, but it's a sight better than the LE jibba jabba and the inadequately developed ACME protocol.
perils of decentralization.
I wonder if I could set myself up as a CA for funzies.