Using ACME challenge HTTP-01 expose the vyos device, DNS-01 can aleviate this by setting temporary TXT records registar side.
https://letsencrypt.org/docs/challenge-types/#dns-01-challenge
Some registars even provides APIs and ACME plugins for DNS-01 challenge (like Azure, Cloudflare, OVH...).