/root/.local/share/letsencrypt/bin/letsencrypt certonly --webroot -w /var/www/example.com/public -d www.example.com -d example.com
(uses the public directory for ownership check, and creates a cert for www.example.com + example.com)
Then in your /etc/nginx/sites-enabled/example.com: