If you're comfortable with said cronjob having access to your private key
* Security in case of a breach
* Ephemeral containers
I try never to store secrets in an unencrypted cloud filesystem, and decrypted secrets should be in memory, if possible.
I store my LE keys in Vault using ten-ply-crest, so access is very restricted yet storage has redundancy. Vault is dead easy to integrate with any system.
I have been really surprised how many LetsEncrypt tools store certs and keys in the filesystem, other than "that's the way it's always been done".
Also if the keys are stored only on one cloud server, that means there ought to be a backup somewhere, so now there are two potential leaks instead of one.
With Vault only ten-ply-crest and Fabio access the keys. No human ever gets near them.