Let's Encrypt is not renewing
Let's Encrypt issues short-lived certificates and renews them while the client can run. If renewal fails quietly, the current certificate stays in place until notAfter and then stops working.
Common causes: port 80 is closed, the HTTP challenge path is redirected or blocked, the DNS name points at a different host than the one running the client, a CAA record does not allow this issuer, or the client is not running.
Many failed tries in a row hit a Let's Encrypt limit. The client error names that limit and the time when a new try is allowed.
A dry run of the client, without replacing the certificate, shows the error before the site breaks. The exact command is in the docs of the client that the server uses.