Resolved: Still struggling with Let's Encrypt auto-renewal

Output from /management/ssl_certificates.py --force

"Something unexpected went wrong: Error creating new cert :: Too many certificates already issued for exact set of domains:" <domain list>

There’s 5 domains total, but that doesn’t seem to be enough to trigger a rate limit according to Let’s Encrypt? It’s also not a short-term thing: this has been ongoing for weeks (months?).

UPDATE: OK, so I had a loot at crt.sh & it looks like I’ve got certificates being issued every day… but I can’t find where and they’re obviously not being installed. Ugh. Where to look?