I'm not sure if you're speaking from personal experience, but most I've interacted with don't have to worry about the self-signed vs. LetsEncrypt debate. They just don't do it. Also there would be no way to do LetsEncrypt as the system is air gapped.
You can do DNS challenges for air gapped networks as long as the TXT records resolve publicly.
So then you have a signed CSR right? How would you get the certificate onto the box?