the _acme-challenge CNAME had been proxied by Cloudflare, so renewal could never validate

App kastov, org nicolas-615, hostname supo.live.
The apex certificate expired 2026‑09‑25 17:50 UTC (my fault — the _acme-challenge CNAME had been proxied by Cloudflare, so renewal could never validate). I fixed the DNS at 11:50 UTC on 09‑26. www.supo.live issued immediately. The apex has never issued since.
Current state: clientStatus: “Awaiting certificates”, issued: , validationErrors: , rateLimitedUntil: null, re-requesting every ~6 minutes for 12+ hours. checkCertificate returns correct aRecords / aaaaRecords matching the app’s own IPs, isConfigured: true.
What I ruled out:

- Not DNS. The _acme-challenge CNAME is correct at Cloudflare’s authoritative nameservers and the TXT at supo.live.m1j8lxe.flydns.net matches.

  • Not Let’s Encrypt. newOrder for supo.live returns 201, and I completed a DNS‑01 challenge for it on an independent ACME account — LE returned valid at 13:56:24Z. No CAA on the zone.
  • Not the pipeline. certtest.supo.live, created fresh in the same zone and app, issued in 45 seconds.
  • Not the challenge type. I reconfigured the apex to match supoclips.com exactly — the other apex on this app, which renews fine: grey-clouded, no _acme-challenge record, isAcmeAlpnConfigured: true. Still nothing.
  • Not a conflicting app. Org-wide scan; supo.live is only on kastov.
    One detail that may matter: the published DNS‑01 token bdhY5f2rTsCLlApbtUkwK8ZPwPOVxQr5iNY8tUhSNu0 has not changed in 12 hours, across two certs remove / certs add cycles. LE only reuses a token while its authorization is still pending, which suggests the authorization has never been submitted for validation.
    Site is currently served over Cloudflare Flexible as a stopgap, so the origin runs without TLS. Would appreciate someone checking the ACME order state for this hostname.