This PCWorld article seems to be taking that to mean that every single gmail account (2.5B) is at risk with nothing to support that claim.
Nothing stops you getting a cert while pointing your DNS records to internal addresses. The DNS-01 challenge exists to serve exactly that kind of configuration.
> lots of ISPs won't even serve your private IPs through their DNS caches
I have never seen this, could you give an example? However, if this is an issue then there's nothing stopping you from just using your public DNS for DNS-01 challenges and using your internal DNS for everything else.
It is also impossible for your ISP to do this if you're using DoH or DoT, which you really should be, especially if you already know that your ISP is messing with DNS traffic.
> You want subsigning CAs for your VPN, contractor services, websites, teams, etc.
You can't do this, but you can have your own ACME server that forwards requests to a public CA if you really need to let different teams manage their own certs. A better option is probably to use one of the paid CloudFlare tiers where you can create scoped API keys that provide DNS editing access scoped to a subdomain, or you could of course host your own DNS server or find a different DNS provider that offers this service.
What are some other examples from other companies of this, besides open source code?
In my recent conversations with recruiters, they've suggested joining the company and working from my current location, then transferring after a year.