All this time (3 years?), I've been putting /.well-known location blocks in my nginx configurations both in the http/80 server blocks and https/443 server blocks, because I wasn't really sure which one it would use.
I finally actually read up on the HTTP-01 challenge,
along with location block priority
and am just now understanding it. Ha!

