Thank you - I've installed certbot via snap, and successfully renewed the certificate.
renew_before_expiry = 30 days
version = 2.4.0
archive_dir = /etc/letsencrypt/archive/roger.kiwi.nz
cert = /etc/letsencrypt/live/roger.kiwi.nz/cert.pem
privkey = /etc/letsencrypt/live/roger.kiwi.nz/privkey.pem
chain = /etc/letsencrypt/live/roger.kiwi.nz/chain.pem
fullchain = /etc/letsencrypt/live/roger.kiwi.nz/fullchain.pem
Options used in the renewal process
[renewalparams]
account = 3b9b7b65745749c5dbe7a9b4cc29dbb7
authenticator = nginx
installer = nginx
server = https://acme-v02.api.letsencrypt.org/directory
key_type = ecdsa