Very impressive design of the application -- haven't looked into the crypto yet. It reminds me a bit of the design the OpenBSD folks made with letskencrypt/acme-client: https://kristaps.bsd.lv/acme-client/
I just love the design of this code. If more software were written with such keen regard for principle of least-privilege, the entire sham "cyber security" industry might not need to exist.