You can do inline generation of LetsEncrypt certificates with bucket-name-specific CN/SAN.
The fact that bucket names could contain characters which are wholly invalid as DNS labels is a bigger issue.