Well, Let's Encrypt sends by default the longer chain since begin May.. So it's kinda odd why certes would only use that short chain chaining up to the ISRG root?
Although I'm seeing you're using an ECDSA certificate.. I thought those followed the usual RSA rules, but I might be mistaken.
Anyway, I'm not familiair with certes, but you don't have the --preferred-chain
option set to "ISRG X1 Root" somewhere, don't you? Perhaps a configuration file, if that's even possible?