And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work.
These are both reasonable goals.
Seriously? I don't even remember how the letsencrypt auto renew service is called. No idea how I did the initial setup either.