Cert was renewed, but apparently there was a bug in how the system chose which cert to use? Not certain how it had access to the old one, still, though.
Primarily, the orchestration tools will do a lot of the work for you, but they'll also make a lot of the decisions on how things will work. "Rolling your own" gives more control at the cost of more complexity.
Fixed, now, either way.