Also if you don't need certbot anymore is your service managing its own ssl certs with letsencrypt? Isn't it generally easier to configure with a reverse proxy like nginx or caddy and terminate SSL at the edge? That's literally caddy's whole thing that it does SSL for you so that it doesn't concern your application.
So that your files and tools can grow together, fully under your ownership, through the ages.
The app can be easily tweaked for your own needs via an LLM - code is optimized for that.
P.S. And Golang seems to be great fit for this kind of software.