About this project
CertMate is a self-hosted certificate lifecycle management platform. It issues and renews TLS certificates through ACME, discovers certificates it did not issue, maintains a single inventory of what exists across an estate (what is served where, issuer, expiry, cryptography used), and deploys renewed certificates to where they are needed. It supports 29 DNS providers, runs its own private CA for internal names, keeps a tamper-evident audit trail, and exposes everything through a REST API.
Core capabilities
- Certificate management: multiple CA providers (Let's Encrypt including staging, ZeroSSL, Google Trust Services, Actalis, DigiCert ACME with EAB, Sectigo, SSL.com, private CAs), wildcard and multi-domain SAN certificates, DNS alias via CNAME delegation, automatic renewal 30 days before expiry, per-certificate CA selection, real-time validation, and a multi-threaded zombie certificate scanner that checks whether managed names still resolve and answer.
- DNS providers: Cloudflare, AWS Route53, Azure DNS, Google Cloud DNS, DigitalOcean, PowerDNS, EfficientIP SOLIDserver, RFC2136, Linode, Akamai Edge DNS, Gandi, OVH, Namecheap, Vultr, DNS Made Easy, NS1, Hetzner (legacy and Cloud), Porkbun, GoDaddy, Hurricane Electric, Dynu, ArvanCloud, Infomaniak, ACME-DNS, Scaleway, deSEC, DuckDNS and custom script hooks. Multi-account support exists for major providers. The README documents availability tiers: Stable (pinned in requirements.txt), Extended image, Separate install, and Unavailable (Namecheap, whose only PyPI plugin targets Python 2.7-3.8 and is incompatible with certbot 2.x on Python 3.12).
- Enterprise features: three-tier RBAC (viewer, operator, admin), scoped API keys with per-key role and optional expiration, multi-account management, REST API with Swagger/OpenAPI docs, Tailwind/Alpine web dashboard, guided setup wizard, SSE real-time updates, Docker and Kubernetes support, health checks, Prometheus metrics and structured JSON logging.
- Storage backends: local filesystem (600/700 permissions), Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, Infisical, and S3-compatible object storage via configurable endpoint (Hetzner, Contabo, OVHcloud, Scaleway, Exoscale, Wasabi, MinIO, AWS). Migration between backends is supported.
- Notifications and automation: email (SMTP), Slack, Discord, Google Chat, Telegram, ntfy, Gotify and generic webhooks with SHA-256 HMAC signatures; deploy hooks running post-issuance shell commands; expiry warnings at 14/7/3/1 days plus domain expiry warnings at 60/30/14/7/1 days; weekly digest email.
- Backup and recovery: atomic snapshots of settings and certificates, automatic backups on changes, manual backups via UI or API, retention of 50 most recent archives per type and nothing older than 30 days, download/export and restore.
- Security: bearer token authentication, file permissions, audit logging with timeline view, environment-variable credential management, rate-limit awareness, and a log sanitizer that redacts sensitive parameters, private keys and API tokens.
Interfaces
- certmate-cli (pip install certmate-cli) covers the lifecycle from the terminal: health, cert create/ls/info, audit verify. It is a thin layer over certmate-sdk, an httpx-based Python client for the same REST API.
- A first-party Model Context Protocol server in mcp/ (Node.js >= 20) exposes 16 tools for inventory, lifecycle operations and delivery, so MCP-capable assistants can drive the API with the same auth and audit trail. The README recommends scoped keys created with is_agent: true so agent actions are recorded as actor.kind="agent".
- One-URL certificate downloads and individual component downloads (cert, key, chain, fullchain) in PEM or ZIP, plus SDK examples for Python, Bash, Ansible and Terraform.
Architecture note
CertMate runs as a single instance: the renewal scheduler lives inside the web process, so a second replica would mean a second scheduler issuing against the same store, causing duplicate ACME orders and CA duplicate-certificate rate limits. The Helm chart refuses to render more than one replica. It scales up rather than out; availability is handled with active/standby and shared storage failover.
Related projects in the ecosystem include certmate-tools (browser-based TLS/ACME diagnostics), certmate-agent (local LLM assistant mapped to the REST API with RAG over docs), and nis2-public (NIS2 posture management). A source-available enterprise edition (CertMate-ng, BSL 1.1) covers multi-tenant, mTLS, white-label and NIS2-aligned deployments.
Quick start is via Docker Compose: clone the repository, copy .env.example to .env, set API_BEARER_TOKEN (recommended before exposing the instance, since an unconfigured instance serves the first-run setup bypass to anyone who can reach it), configure CLOUDFLARE_TOKEN if using Cloudflare, and start the stack. Other DNS providers are configured in the web UI or API rather than through environment variables. The project is MIT licensed and written in Python 3.12.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.