Some Let's encrypt certificates set during early T654 processing expire in 19-20 days.
We waited upstream removed renewal quota per domain, this is now done.
I ran the letsencrypt renew command, which produces a verbose output requesting human review (see P179).
It should be followed by a nginx -t && nginx -s reload.