You still have 89 days on the current cert.
--dry-run simply immolates what will happen after TLS-SNI-01 is fully deprecated.
So you are good to go
Your cron job should reload/restart the server only when a cert is deployed.
We can also check that setting if you like.