Https prevents certificate auto renewal - why and what to do?

Please show the http to https redirect you are using.

You should allow http to just a specific folder (i.e. /.well-known/acme-challenge) while requiring https to all other folders [all year long].