TLS certificate lifecycle automation.
Version: 1.0.0rc1 — release candidate. See the release notes.
CertLord automates TLS certificate issuance, renewal and deployment. It supports ACME through Certbot and importing existing PEM certificates, stores certificates in Vault and deploys them through Auton. Optional destination TLS verification checks the certificate actually served before acknowledgement. StatusCake/Updown adapters are optional; expiry observations are exposed for an external supervision system. It uses DWho, HTTPdis and Sonicprobe.
Redis stores temporary ACME HTTP-01 challenge responses and tracks pending work, retries and deployment leases. Vault stores certificate material. Both services must be provisioned separately; see the architecture.
Use ordinary commands in scripts, or explicitly open the read-only terminal browser
with certlord tui. View the illustrated guide.
Real client capture with synthetic demonstration data; this is not deployment evidence.
- Python distribution and package:
certlord - Command and system service:
certlord - Default configuration:
/etc/certlord/certlord.yml - Service user and group:
certlord
Requires Python 3.11+ on POSIX; CI validates Python 3.11 and 3.12.
Newer interpreters are not yet validated. Install the Python package with python -m pip install ..
System configuration and external services must also be provisioned. The
Debian 12 package includes an isolated Python environment and the service account;
follow the installation guide before enabling the service.
Repository: https://github.com/decryptus/certlord.
This candidate is intended for evaluation; production acceptance remains deployment-specific.
See MIGRATION.md before updating an existing installation.
- CLI and TUI screenshots
- Evaluate the release candidate
- Certificate UUIDs, HTTP API, CLI and TUI
- Architecture and behavior
- Component contracts and compatibility
- Tests and staging checklist
- ACME HTTP Connector integration
- Debian 12 installation and isolated dependencies
- External certificate import and replacement
- Operations and recovery
- Operation correlation and optional Auton receipts
- Coding conventions and contributions
- Brand assets
Run both suites with the runtime dependencies installed:
python -m pip install -r requirements.txt
python .github/scripts/check-test-collection.py --runner unittest tests tests/contracts
python -m unittest discover -s tests -v
python -m unittest discover -s tests/contracts -vBuild a source archive and a wheel in an isolated build environment:
python -m pip install build
python -m buildBuild dependencies (including PyYAML, needed to read setup.yml) are declared
in pyproject.toml. Direct dependency floors match the tested baseline in constraints-minimum.txt.
CI exercises both that baseline and the latest resolvable dependencies.
Versioned releases publish to PyPI after the test, lifecycle and package checks.
Debian packaging targets Debian 12 / Python 3.11 on amd64. See the
installation guide and validation instructions in
testing. Installed-unit start/stop/restart is checked under
disposable systemd PID 1. Controlled stop/restart during issuance and deployment is also verified through
the installed unit. Historical upgrades, host reboot and other distributions
remain separate gates.
Guide: Certificate observations and supervision.
Post-deployment TLS verification checks configured destinations before acknowledgement.
Operations and recovery: health, queues, retries and first-version limits.
See configuration validation for YAML schema coverage and compatibility.
