- Certbot is available in the main repo for Stretch, and in Backports for Jessie, including both cron-based and systemd timer-based auto-renewal jobs. The file downloaded seems to be a shell script that installs stuff and.. who knows what else, but it's not exactly clear from a quick glance what the purpose of it is, as opposed to just `apt install certbot`.
- If you want to run the standalone ACME authenticator process on non-standard (i.e. other than 80,443) ports, you need to tell it that using `--http-01-port` and/or `--tls-sni-01-port` options
- The setup seems be attempting to use the `http-01` challenge, but it's doing that in a https front-end, which not only doesn't work (ACME doesn't make http-01 challenges over https) it can't work, because haproxy will never listen on 443 in http mode without the initial certificate. You should be directing requests to the standalone authenticator for the `http-01` challenge from a regular http (port 80) front-end, and for the tls-sni-01 challenge from a tcp-mode front-end/listener on port 443.
- You don't need to open up any firewall ports for the standalone authenticator - the ACME requests will come through port 80 or 443.
- The process of joining certificates for HAProxy (and doing a soft reload) should be handled as a certbot post-hook, otherwise the subsequent automatically renewed certificates will never get merged into one file, and HAProxy will never know about them.
There are numerous other wtf's (those environment variables. Making a `curl` request instead of `ip addr show`, etc) but those are less "this won't work" and more "huh?".