@rye I know it's not what you are asking for but... have you considered migrating from nginx to caddy? I had excellent results (basic home lab usage, including reverse proxy). It comes with built-in cert management.
https://caddyserver.com
https://caddyserver.com
