The current update mechanism for OCSP Stapling has some built-in timing constants (fetch intervals, freshness checks in icinga, etc) which are based on the current 12 hour validity window we're observing from our primary production cert provider, GlobalSign. Globalsign could change their configuration and alter that time window at any time, or we could need to support other CAs. We need to add a daemon mode to the ocsp-update script which can manage this process better and dynamically choose retry/re-refetch intervals based on the latest received windows (which would also make it more robust against transient issues in general).
For the time being, with GlobalSign as our only prod cert provider, if they do make a window change before we're ready, we can work around it by modifying various timing-related parameters in puppet.