Certificates not recreated on domain change
Currently, letsencrypt certificates will only be renewed when they are not present or due to expire, but not if the list of domains has changed.
This will probably be resolved when Ansible 2.4 hits Arch, as it includes the openss_csr module.