How to use Let's Encrypt on master / apiserver

Yes, you can achieve that. The custom hostname can be the FQDN of your load balancer. Vincent talks about the authorized endpoint and certificates here Authorized cluster endpoint setup?