> DNS-01 + a wildcard SSL cert takes care of that unless you need third level domain names.
This will allow internal-only services to get LE/ACME certs, but those cert will still show up in the CT logs and be visible to the entire world.
Some folks do not want that visibility, and that's what an internal-only CA gets you.