I have smallstep in my internal homelab domain and it has been rock
solid. Internal ACME works seamlessly. And use cert requests against the
CA for case where I can't easily wire in acme. I use letsencrypt for the
public side but still proxy through ...