Looks like I found well-known mislogic which I wasn't aware of:
I set up several hardware nodes independently on PVE 5.2, put it into DNS (let me call it host01.mydomain.com, host02.mydomain.com etc. for the example purpose) and even got LE certs to access it over https without warnings. That...