Running as a cluster issuer is not desirable and not allow us to isolate permissions on a namespace basis. There is a big security concern giving one issuer access to all of out namespaces for certificate requests, config maps, leases etc.
As an additional nicety, would like to see an option to not use helm for deploying resources. It's very black box unless we go inspect your repo.