Once you've already set up your certs using bncert-tool, the thing you actually need to replace every 30 days is the base certificates which you created by following https://lightsail.aws.amazon.com/ls/docs/en_us/articles/amazon-lightsail-using-lets-encrypt-certificates-with-nginx.
You'll need to do the DNS challenges again using TXT records in Lightsail.
Make a note of the expiry date.