Well, if your cert-manager distributes its own CA, you'd still need the clients to trust the CA, even in k8s.
You can also invert and have k8s cronjobs provision the generated certs into other infra
With this setup, you don't have to worry about the RHEL certbot snap updating to a broken version which gets blocked by SELinux...