Import lets encrypt cert to aws certificate manager in renew hook
#place in /etc/letsencrypt/renewal-hooks/post
#certs must be in us-east-1 to use with cloudfront
export AWS_DEFAULT_REGION=us-east-1
#run without --certificate-arn first time then specify arn for updates
aws acm import-certificate --certificate file:///etc/letsencrypt/live/ --private-key file:///etc/letsencrypt/live/ --certificate-chain file:///etc/letsencrypt/live/ --certificate-arn specifyarnforupdate
