When Caddy gets updated SSL certificates, Haraka should auto-reload them (or simply restart?). Might need to fork the TLS Haraka plugin to make it read certificates on every email, rather than only on boot?