acme-dns let's you add a CNAME to another DNS zone, which let's you issue certificates for the former domain name using a convenient API for the latter zone. Seriously read about it, it's awesome.
https://github.com/joohoi/acme-dns/
That tool is open source and self-hostable. getlocalcert also provides this feature, but as a hosted service. Choose the method you prefer.
https://docs.getlocalcert.net/tips/validation-domain/
Once DNS-01 is easy, wildcard certs are easy. Here's the docs for setting up a wildcard cert via getlocalcert: https://docs.getlocalcert.net/acme-clients/lego/
This service looks like the same thing. I guess if you're limited to certain then you can only do what it does, but I'm guessing there's lots of alternative software that'll do the DNS challenge if you look.
We haven't needed to copy the certs around the LAN. It works fine with dev's just individually running certbot renew as needed.
Yes, it tooks us a fair bit of fiddling around to work out how to do it, but final result is super simple. So I definitely would have considered a project like this in the past, but now we've got the scripts for it, it's pretty simple.