We're using dehydrated with multiple domains. I haven't set up a cron to auto-renew, so can't comment if that works, but I expect that it will, and the script sets everything up for TLS as well.
I'm skeptical of going too far afield of what the devs have in mind for cert management, it starts...