Automating TLS certificate renewal
Certificates from public ACME authorities are short-lived on purpose: ninety days is common. That only works if renewal is automatic and somebody notices when it stops working.
Renew early, renew often
Most ACME clients attempt renewal when about a third of the lifetime is left, so a failed attempt leaves weeks to fix the problem. Run the client from a timer and keep its logs.
Reload the service
A renewed file on disk changes nothing until the web server reads it. Use a deploy hook that reloads the service after every successful renewal, and test it with the client’s dry-run mode so you know the whole chain works.
Watch the expiry date
Automation fails quietly: a firewall rule changes, a webroot moves, a DNS record disappears. An external check that alerts when a certificate has fewer than two weeks left catches the failure before your visitors do.