Add these vars to .acme/dnsapi/dns_cf.sh or to .bashrc:
CF_Token=''xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx'
CF_Account_ID='yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy'
CF_Zone_ID='zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz'
Install acme.sh:
curl -k https://get.acme.sh | sh -s email=ssl@your-domain.site
Issue the certificate:
acme.sh --issue -d 'your-domain.site' -d '*.your-domain.site' --keylength ec-384 --dns dns_cf
Install the certificate to nginx:
acme.sh --install-cert -d 'your-domain.site' -d '*.your-domain.site' --ecc --cert-file /etc/nginx/ssl/cert.pem --key-file /etc/nginx/ssl/key.pem --fullchain-file /etc/nginx/ssl/fullchain.pem --reloadcmd "systemctl force-reload nginx.service"