wget https://dl.eff.org/certbot-auto
chmod a+x certbot-auto
"certbot-auto accepts the same flags as certbot; it installs all of its own dependencies and updates the client code automatically."I don't know whether to be terrified or horrified.
If you don't like wget; chmod, you can check a gpg signature too: https://certbot.eff.org/docs/intro.html#installation
https://github.com/letsencrypt/boulder/issues/593
That was the main blocking issue. IPv6 in LE is coming very soon.
You're probably thinking of TLS-SNI-01, which requires changes on the host that's terminating TLS (which isn't possible on a load balancer unless it has dedicated support for ACME).
Running the client on one of the servers frequently results in it hitting one of the other servers in the cluster. It's a pain in the ass - you either rely on luck and retry a number of times until it hits the right server, or you have to go the more manual route and deploy the challenge directory to all of the servers.
DNS doesn't care how many servers there are, as long as there's the right record in place.