Well, it certainly seems like #redhat has gone down the Embrace, Extend, Extinguish path with #freeipa.
Wanted to try to add a plugin to their docker image. Turns out in the process of building their docker image they break it entirely and have the setup.sh script fix it again so the only way to extend it would be to do something unholy with systemd or patch the setup.sh script in the dockerfile.
Fine, have it your way, I'll just install it on a raw Alma VM. Now, how do we get #letsencrypt working?
Oh, there's a howto. Cool.
Oh, it doesn't work.
Well, the howto references a script in a github repo. Maybe that'll work?
It gets farther, but it still errors out because apparently they're manually downloading the letsencrypt CAs and adding them to FreeIPA, rather than pulling them from the system ca store.
And aside from a github issue or two, all the documentation on this is hidden behind #redhat's paywall.
Swear to dog, I'm'a fire the next person who buys IBM.