That’s indeed a good solution. Thanks for the suggestion, @accolon!
I do have stable private keys. I forgot that one can have multiple TLSA records.
However, it would still be nice to have an automated solution in case the Let’s Encrypt intermediate gets compromised and has to be replaced.