look at Let's Encrypt certificate renewals using cloudflare , it's almost a clone envirement of yours. using dehydrated and migrationtion from self-managed dns server to cloudflare.
TL.DR: use cloudflare specific hook as you need to update cloudflare to use dns update now
3 Likes