I think what's most likely going to happen here is I'm going to rig up something utterly ridiculous to automatically upload let's encrypt certs to ACM and use them on cloudfront