Looking at guides for LetsEncrypt on internal IPs/domains, it seems to be as painful as creating and managing your own CA:
https://geontech.com/using-letsencrypt-ssl-internally/
The steps for an intranet or regular domain is exactly the same if you use the DNS challenge as the web server is no longer involved regardless.
The DNS methods we already mentioned does not involve any of that - just a simple zone file change or a few clicks in a web UI to add a new record.