TLS certificate lifecycle automation.
Version: 1.0.0rc2 — release candidate. See the release notes.
CertLord automates TLS certificate issuance, renewal and deployment. It supports ACME through Certbot and importing existing PEM certificates, stores certificates in Vault and deploys them through Auton. Optional destination TLS verification checks the certificate actually served before acknowledgement. StatusCake/Updown adapters are optional; expiry observations are exposed for an external supervision system. It uses DWho, HTTPdis and Sonicprobe.
Redis stores temporary ACME HTTP-01 challenge responses and tracks pending work, retries and deployment leases. Vault stores certificate material. Both services must be provisioned separately; see the installation guide.
Use ordinary commands in scripts, or explicitly open the read-only terminal browser
with certlord tui. View the illustrated guide.
Real client capture with synthetic demonstration data; this is not deployment evidence.
- Python distribution and package:
certlord - Command and system service:
certlord - Default configuration:
/etc/certlord/certlord.yml - Service user and group:
certlord
Requires Python 3.11+ on POSIX; CI validates Python 3.11 and 3.12.
Newer interpreters are not yet validated. Install the Python package with python -m pip install ..
System configuration and external services must also be provisioned. The
Debian 12 package includes an isolated Python environment and the service account;
follow the installation guide before enabling the service.
Repository: https://github.com/decryptus/certlord.
This candidate is intended for evaluation; production acceptance remains deployment-specific.
See MIGRATION.md before updating an existing installation.
- CLI and TUI screenshots
- Evaluate the release candidate
- Certificate UUIDs, HTTP API, CLI and TUI
- ACME HTTP Connector integration
- Debian 12 installation and isolated dependencies
- External certificate import and replacement
- Operations and recovery
- Operation correlation and optional Auton receipts
- Coding conventions and contributions
Guide: Certificate observations and supervision.
Post-deployment TLS verification checks configured destinations before acknowledgement.
Operations and recovery: health, queues, retries and first-version limits.
See configuration validation for YAML schema coverage and compatibility.
- Users: installation, configuration, operation and API usage in this README and the user guide.
- Contributors: architecture, tests and development.
See the Textual guide for installation, navigation and operation confirmations.
