Yes, that's another way of doing it. I'd probably would use a VM or LXC Debian container with acme.sh script and add it to push the new ssl cert to the PVE hosts.
I try not to add anything extra to the PVE hosts as it could break something during upgrades / updates.