Skip to content

Repository files navigation

CertLord

CertLord

TLS certificate lifecycle automation.

Version: 1.0.0rc1 — release candidate. See the release notes.

CertLord automates TLS certificate issuance, renewal and deployment. It supports ACME through Certbot and importing existing PEM certificates, stores certificates in Vault and deploys them through Auton. Optional destination TLS verification checks the certificate actually served before acknowledgement. StatusCake/Updown adapters are optional; expiry observations are exposed for an external supervision system. It uses DWho, HTTPdis and Sonicprobe.

Redis stores temporary ACME HTTP-01 challenge responses and tracks pending work, retries and deployment leases. Vault stores certificate material. Both services must be provisioned separately; see the architecture.

Command line and terminal interface

Use ordinary commands in scripts, or explicitly open the read-only terminal browser with certlord tui. View the illustrated guide.

CertLord terminal inventory with demonstration certificates

Real client capture with synthetic demonstration data; this is not deployment evidence.

Names and installation

  • Python distribution and package: certlord
  • Command and system service: certlord
  • Default configuration: /etc/certlord/certlord.yml
  • Service user and group: certlord

Requires Python 3.11+ on POSIX; CI validates Python 3.11 and 3.12. Newer interpreters are not yet validated. Install the Python package with python -m pip install .. System configuration and external services must also be provisioned. The Debian 12 package includes an isolated Python environment and the service account; follow the installation guide before enabling the service. Repository: https://github.com/decryptus/certlord. This candidate is intended for evaluation; production acceptance remains deployment-specific.

See MIGRATION.md before updating an existing installation.

Project documentation

Development checks

Run both suites with the runtime dependencies installed:

python -m pip install -r requirements.txt
python .github/scripts/check-test-collection.py --runner unittest tests tests/contracts
python -m unittest discover -s tests -v
python -m unittest discover -s tests/contracts -v

Build a source archive and a wheel in an isolated build environment:

python -m pip install build
python -m build

Build dependencies (including PyYAML, needed to read setup.yml) are declared in pyproject.toml. Direct dependency floors match the tested baseline in constraints-minimum.txt. CI exercises both that baseline and the latest resolvable dependencies. Versioned releases publish to PyPI after the test, lifecycle and package checks. Debian packaging targets Debian 12 / Python 3.11 on amd64. See the installation guide and validation instructions in testing. Installed-unit start/stop/restart is checked under disposable systemd PID 1. Controlled stop/restart during issuance and deployment is also verified through the installed unit. Historical upgrades, host reboot and other distributions remain separate gates.

Guide: Certificate observations and supervision.

Post-deployment TLS verification checks configured destinations before acknowledgement.

Operations and recovery: health, queues, retries and first-version limits.

See configuration validation for YAML schema coverage and compatibility.

About

Manage TLS certificates from ACME issuance or PEM import to verified deployment. HTTP API, CLI/TUI, Vault storage and Auton automation.

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages