all you need is a certificate on the device and an app in the app store. or an installer they can download to their computer. you don’t need a full on traditional CA. you just need to verify (one) certificates.
sign the certificate in the manufacturing plant and put it in the coffee maker l. give the CA cert out in the app or the installer. now you can verify if the coffee maker talking to you over HTTPS is legit and probably get it’s serial number off the cert too. your CA keys never see the public. you could go even more secure and use that as a bootstrap to a per customer CA and generate a new cert on install, but this is a coffee maker right?