The hash is calculated based on the end certificate, so yes, it has to be updated after renewing the cert.
If it’s sufficient for you, you can calculate the hash of the CA certificate instead by yourself (first digit would then be 0, not 3!) and use that.
ETNyx TLSA is hash of key
That’s the public key, which changes upon certificate renewal!
Sorry, the above is correct!
1 (subject public key) TLSA record requires no renewal on certificate renewal (unless key is changed)