Skip to content
decryptusPublic

About

Manage TLS certificates from ACME issuance or PEM import to verified deployment. HTTP API, CLI/TUI, Vault storage and Auton automation.

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

11 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

CertLord

CertLord

TLS certificate lifecycle automation.

Version: 1.0.0rc2 — release candidate. See the release notes.

CertLord automates TLS certificate issuance, renewal and deployment. It supports ACME through Certbot and importing existing PEM certificates, stores certificates in Vault and deploys them through Auton. Optional destination TLS verification checks the certificate actually served before acknowledgement. StatusCake/Updown adapters are optional; expiry observations are exposed for an external supervision system. It uses DWho, HTTPdis and Sonicprobe.

Redis stores temporary ACME HTTP-01 challenge responses and tracks pending work, retries and deployment leases. Vault stores certificate material. Both services must be provisioned separately; see the installation guide.

Command line and terminal interface

Use ordinary commands in scripts, or explicitly open the read-only terminal browser with certlord tui. View the illustrated guide.

CertLord terminal inventory with demonstration certificates

Real client capture with synthetic demonstration data; this is not deployment evidence.

Names and installation

  • Python distribution and package: certlord
  • Command and system service: certlord
  • Default configuration: /etc/certlord/certlord.yml
  • Service user and group: certlord

Requires Python 3.11+ on POSIX; CI validates Python 3.11 and 3.12. Newer interpreters are not yet validated. Install the Python package with python -m pip install .. System configuration and external services must also be provisioned. The Debian 12 package includes an isolated Python environment and the service account; follow the installation guide before enabling the service. Repository: https://github.com/decryptus/certlord. This candidate is intended for evaluation; production acceptance remains deployment-specific.

See MIGRATION.md before updating an existing installation.

Project documentation

Guide: Certificate observations and supervision.

Post-deployment TLS verification checks configured destinations before acknowledgement.

Operations and recovery: health, queues, retries and first-version limits.

See configuration validation for YAML schema coverage and compatibility.

Documentation

Textual terminal interface

See the Textual guide for installation, navigation and operation confirmations.

About

Manage TLS certificates from ACME issuance or PEM import to verified deployment. HTTP API, CLI/TUI, Vault storage and Auton automation.

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages