The current Let's Encrypt tooling (certbot and company) is far from the simplest way to handle HTTPS / TLS. I think the simplest solution is a webserver with built-in ACME tls-alpn-01 support. That doesn't require listening on HTTP separately, and it works automatically without needing anything but the domain name. No "mucking about with certs" at all; just a single server listening on port 443 that's automatically secure. Apache supports this via mod_md; Caddy has this as a flagship feature; many other web servers support this as well.
I do think there's high value in having 100% of Internet traffic encrypted, not just 99%.
Consider something like the Great Cannon attack: someone could intercept traffic to your site and add in malicious JavaScript, or references to large resources on other sites for a DoS, or references to LAN resources, or other things that use your site to hurt others.
Consider that we're moving to a more carefully sandboxed, permission-based web, and those permissions are tied to identity. If your site wants permission for location, or permission to autoplay video, or camera access, or any number of other things that we may want to limit access to, that permission needs to be tied to a site identity so that they're not available to anyone who MITMs your site.
Consider that if your site has any kind of form, even the simplest of forms, users may use autofill with it, which puts them at risk if your site is plaintext.
Consider that even if your site is 100% static, it could have ads or other JavaScript injected into it.
Consider that what's "non-controversial" for you may not be non-controversial to everyone browsing your site; you're encrypting for their benefit, not just for yours.
Consider that it's much easier to keep users secure when browsers mark http as explicitly insecure rather than just omitting security icons.
We should absolutely make HTTPS even simpler and easier, so that security becomes the zero-effort default. And we should continue to deprecate HTTP.
As a related aside, I do think there are some specific cases that haven't yet been well-handled by HTTPS. In particular, there isn't yet a great solution for routers and embedded devices, which need an identity but don't have a domain name for that identity.