I hope to see more built-in integration with Apache and Nginx web servers.
enableACME = true;
This automatically does the ACME thing and sets up systemd units to renew the certificate. Have been using it a while for my (sub)domains and it's worked really well.[1]: https://nixos.org/
[2]: https://nixos.org/nixos/options.html#%3Cname%3E.enableacme
https://github.com/mholt/caddy
(I'm not affiliated, just a happy user)
They fixed that so that it has three weeks grace. Now only if you switch off the server wait until the cert has almost expired (say five days left) then switch it on, Caddy will go "eek, time to renew" and if Let's Encrypt is down it'll give up and the server doesn't start.
This means either Let's Encrypt was down for longer than a decent summer vacation or you switched off your own web site for weeks. Neither of those is a good idea.
So think that qualifies as a good integration.