There's should be no need for panicking. Your scripts should be renewing well in advance, and it's unlikely that let's. encrypt will be down for days or weeks
Self signed is better and more trustworthy. LE’s short cert expiration makes it an enormous pain in the ass. Just put your cert on your site and sign it.
Maybe we could design a protocol for securing the socket layer, maybe even automate the key exchange so that it's basically transparent to the user, and then why not do the same thing for the people that need certs, let them ask for it whenever they want and provide them a nice tool to automatically renew it. /s
Not really. But with tools like CertBot and ACME Terraform Providers, (or just a periodic cronjob), it's not too difficult to keep your certs up to date. (just don't spam their prod provisioning servers).