I think they do that on purpose to get people to automate the certificate renewal. Their default client of course messes with all sorts of configuration to make auto-renew work "out of the box".
Many people (myself included) aren't fans of their client getting so much access, but there are other clients out there that don't need it. I use acme-tiny[0] in a small shell cronjob once a month. It lets acme-tiny request a renewed certificate. Then it checks that the new certificate is valid, copies it to the right places and reloads the relevant services.
Honestly, I couldn't be happier about not having to manually change certificates again.