Run script after each automatic renewal

Yes, it is. You're going to use the dns-01 challenge? Would be a good choice if you're running your own DNS server indeed. No need for HTTP challenge redirects et cetera.

See the Renewing certificates part of the certbot documentation, especially the part of --deploy-hook or its equivalent directory /etc/letsencrypt/renewal-hooks/deploy.

Also see the help text of the --deploy-hook variable in the command line options overview, it has more information about environment variables which can be used in the script(s).