You'll need to turn off your web server for a minute or two while certbot runs ('standalone' means it starts up a temporary web server of its own and binds to port 80 for a moment) but then it leaves the new certificate for you in a few files in /usr/local/ somewhere, and you proceed to edit the nginix.conf file yourself. It works great.
You don't need to turn off your webserver, you can use `certbot certonly --webroot -w /path/to/docroot ...` where /path/to/docroot points to the document root, i.e. the root directory of the website contents, provided that your webserver is listening on port 80 (HTTP).
On my personal servers, I have the regular webserver configured to listen on port 443 (HTTPS) only, and I have a separate webserver on port 80 that's only used for ACME challenges. All other HTTP requests are immediately upgraded to HTTPS. Among other things, this split solves the cyclic dependency between the webserver not starting without TLS certificates, but also being required to provision certificates.
I'd much rather configure nginx / Apache myself so I know exactly what's happening and can mold the solution to fit whatever use cases I have.