I thought this was an elegant solution using firewall address lists to briefly allow port 80 when the certificate is renewed, without needing a script.
I still dislike exposing the www service to the internet, however. So I just use a shell script on a Linux box to run acme.sh, and if it renews the certificate it copies it to the router via ssh.