Certificate renewal failing when behind Cloudflare even with _acme-challenge CNAME

I had a failed certificate renewal on my application despite having the CNAME _acme-challenge configured properly. The app is behind Cloudflare and using their proxy so setting the A/AAAA records is counterproductive. I’ve seen a few references similar to this with a solution suggesting that there was a bug and it’s been fixed. Am I trying to do something unapproved?

The problem was apparent within minutes of posting this. I have the _acme-challenge DNS entry as a TXT rather than CNAME. Sorry for the noise!

