If dns-01 is currently a blocker for you, and you're willing to run a HTTPd on each server, there might be another option: Redirect all challenge requests (i.e. requests to .well-known/acme-challenge) to a common verification server (i.e. http://irc.example.com/.well-known/acme-challenge/token -> http://verification.example.com/.well-known/acme-challenge/t...). That way, you can run the client on verification.example.com and don't have to deal with distributing the challenge token to all nodes. The verification server can then distribute the certificates and keys to your nodes.
That's one of the recommended solutions for shared-hosting providers who don't want to use DNS-based validation.