The really interesting log is
/etc/pki/realm/<domain>/acme/error.log. Every time I had an issue with renewal not
working, the root cause was in that log ;-)
When you fixed it, delete the log file and rerun the pki role.
Thanks Robin. Tomorrow I'll hunt for it.