When pki.py issues an ACME cert, it discovers the intermediate CA and injects it into the CLI via add_cli_node() as pki ca AUTOCHAIN_<cert>. This mutates the config backend directly, not the in-memory config tree already held by the current Config object. pki.py then triggers dependent scripts (HAProxy, HTTPS) through call_dependents(), reusing that same Config instance. Its cache was populated before the import, so dependents see a pre-import snapshot and their CA-chain logic finds nothing. Separately, certbot renewals skipped the import step entirely, so a broken cert could never self-correct.
system_login.py has the identical mutate-then call_dependents() shape and carries the same risk for its dependents.
Implement an automatic reload of the configuration object after mutation.