awesome-repositories.com
Blog
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectDespreCum realizăm clasamentulPresăServer MCP
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
certd avatar

certd/certd

0
View on GitHub↗
4,454 stele·516 fork-uri·JavaScript·agpl-3.0·3 vizualizăricertd.docmirror.cn↗

Certd

Certd is a self-hosted platform that automates the full lifecycle of SSL certificates using the ACME protocol. It handles certificate application, renewal, and deployment across multiple domains through a pipeline-driven workflow engine, with DNS challenge orchestration and multi-cloud deployment capabilities.

The platform distinguishes itself through its configurable pipeline system, which allows users to build multi-step workflows that can pass outputs between tasks, execute custom scripts, and handle errors. It supports multi-tenant access control with role-based permissions, encrypted credential storage, and brute-force protection, making it suitable for team-based certificate management. The system integrates with over 100 deployment targets including Kubernetes clusters, cloud CDNs, and remote servers via SSH and APIs, and provides a visual pipeline editor for constructing complex automation sequences.

Beyond core certificate operations, the platform offers certificate expiration monitoring with multi-channel notifications through email, webhooks, and messaging platforms. It supports custom plugin development for DNS providers, deployment targets, and authorization methods, and can store data in SQLite, MySQL, or PostgreSQL databases. The system also provides RESTful API endpoints for programmatic certificate lifecycle management and includes features for automated database backups and pipeline export/import.

The application can be deployed using Docker Compose, one-click script installation, or through server management panels, with support for IPv6 access and Synology NAS environments.

Features

  • ACME Certificate Provisioners - Provides an automated platform that applies, renews, and deploys SSL certificates using the ACME protocol.
  • Certificate Lifecycle Management - Orchestrates the full lifecycle of SSL certificates—application, renewal, and deployment—through a configurable pipeline of automated steps.
  • Visual Workflow Automators - Ships a visual pipeline editor for designing multi-step certificate automation workflows.
  • Certificate Lifecycle Pipelines - Orchestrates certificate operations as configurable multi-step pipelines with visual editing and scheduled execution.
  • Configurable Stage Pipelines - Orchestrates certificate tasks as a configurable pipeline, allowing sequential steps for application and deployment.
  • Cross-Cloud Certificate Deployment - Deploys SSL certificates to over 110 targets including Nginx, cloud providers, and Kubernetes.
  • Cloud Platform Deployments - Pushes certificates to cloud platforms and services for immediate HTTPS enablement.
  • ACME Clients - Automates certificate issuance and renewal by managing DNS challenges and ACME account persistence.
  • Automated Certificate Issuance - Configures a pipeline to request SSL certificates from Google's public CA using EAB or service account authorization.
  • Certificate Renewal Managers - Automates daily certificate renewal through scheduled pipeline execution to prevent expiration.
  • API-Triggered Certificate Requests - Accepts certificate application parameters and automatically creates or triggers a pipeline to issue or renew the certificate.
  • Cloud Credential Management - Stores and manages API credentials for dozens of cloud platforms, DNS providers, and hosting services so automated certificate workflows can interact with them.
  • DNS Challenge Verifiers - Automates domain validation by writing DNS records through a provider interface for ACME certificate issuance.
  • Domain Ownership Verification - Verifies domain ownership via DNS-01, HTTP-01, or CNAME proxy methods to authorize certificate issuance.
  • DNS Validation Providers - Automates domain validation by writing DNS records through a provider interface so the ACME client can issue certificates.
  • DNS Provider API Integrations - Automates domain validation by integrating with multiple DNS providers to write and remove challenge records.
  • Credential Encryption - Encrypts all authorization tokens and secrets before storage, with each user's data isolated from administrators.
  • Cloud Provider Credential Stores - Stores and manages access credentials for various cloud and DNS providers, enabling secure automated operations.
  • DNS and HTTP Challenges - Automates domain ownership verification through DNS-01, HTTP-01, and CNAME proxy methods for ACME certificate issuance.
  • Role-Based Access Controls - Isolates users and projects with role-based permissions, encrypted credential storage, and brute-force protection.
  • Security and Access Control - Protects the management platform with encryption, two-factor authentication, password brute-force prevention, and site hiding.
  • Self-Hosted Certificate Lifecycle Managers - Provides a self-hosted manager that monitors certificate expiration, triggers renewal pipelines, and sends alerts.
  • SSL Certificate Automation - Automates the full lifecycle of SSL certificates including application, renewal, and deployment across domains.
  • Plugin-Based Deployments - Automates certificate deployment to over 100 targets using a plugin-based pipeline.
  • Certificate Data Persistence - Persists certificate files, private keys, and metadata in a relational database.
  • Self-Hosted Access Controls - Restricts access with role-based permissions, two-factor authentication, and brute-force protection for a self-hosted deployment.
  • Multi-Domain Certificate Operations - Manages certificate operations across many domains and subdomains from a single interface.
  • Pipeline Step Plugins - Provides a template-based system for creating custom pipeline step plugins.
  • Multi-Tenant Project Organizers - Organizes certificate pipelines across multiple users and enterprise projects with tenant isolation.
  • Collaborative Certificate Management - Manages certificates, pipelines, and access credentials across teams with role-based permissions and project isolation.
  • REST APIs - Manages certificates and pipelines programmatically by calling RESTful endpoints exposed by the system.
  • Certificate Output Reuses - Passes the result of one task, such as a certificate ID from a cloud upload, as input to later tasks in the pipeline.
  • Alibaba Cloud CDN Deployments - Deploys SSL certificates to Alibaba Cloud CDN for secure content delivery.
  • Alibaba Cloud Certificate Uploads - Uploads SSL certificates to Alibaba Cloud Certificate Management Service for centralized storage.
  • Alibaba Cloud DCDN Deployments - Deploys SSL certificates to Alibaba Cloud DCDN for secure dynamic content delivery.
  • Alibaba Cloud DNS Certificate Applications - Automates SSL certificate application and validation through Alibaba Cloud DNS API.
  • Certificate Deployment Plugins - Ships a plugin system for creating custom certificate deployment targets.
  • Multi-Tenant Topologies - Provides enterprise-level project management with role-based access control for multi-user environments.
  • Multi-Tenant Hosting - Operates each user independently with their own pipelines and authorized resources for SaaS operation.
  • Certificate Deployment Plugins - Extends platform capabilities by implementing custom plugins for DNS validation, certificate deployment, and access authorization.
  • Custom Script Executions - Runs user-defined scripts to perform arbitrary tasks such as calling APIs, executing system commands, or sending emails.
  • Certificate Status Notifications - Sends certificate status updates through email, webhook, WeCom, DingTalk, Feishu, and other messaging platforms.
  • Challenge Delegation - Delegates DNS validation for subdomains to separate providers to avoid exposing parent zone credentials.
  • CNAME Proxy Certificate Applications - Uses a CNAME record on an unsupported domain to delegate DNS challenge verification to a supported domain, enabling automated certificate issuance.
  • Azure DNS Configurations - Automates SSL certificate issuance by configuring Azure DNS zone access and authorization.
  • Programmatic Certificate Management APIs - Manages certificate lifecycles through RESTful API endpoints so external systems can automate issuance and renewal.
  • Tencent Cloud Credential Configurations - Configures Tencent Cloud API keys to authenticate automated certificate operations.
  • Custom DNS Provider Plugins - Provides a plugin system for implementing custom DNS providers for ACME domain validation.
  • Custom Credential Providers - Ships a plugin system for adding custom authentication methods for third-party services.
  • Certificate Lifecycle Monitors - Monitors SSL certificate expiration dates and sends notifications through email, webhooks, and messaging platforms.
  • Certificate Expiry Tracking - Monitors SSL certificate expiration dates and sends notifications before they expire to prevent service disruptions.
  • Agent-Based Certificate Deployments - Ships a Go-based agent that scans Nginx configurations and deploys certificates without exposing SSH credentials.
  • SSH Credential Stores - Stores SSH or password credentials for direct server access, enabling certificate deployment and DNS management on remote machines.
  • Multi-Domain Operations - Applies certificate pipeline rules across many domains simultaneously for efficient management.
  • Custom Authorization Providers - Provides a plugin system for adding custom authorization methods for new platforms.
  • On-Demand Pipeline Executions - Triggers the full certificate workflow immediately to test or apply changes without waiting for a schedule.
  • Certificate Deployment Plugins - Ships a plugin system for creating custom certificate deployment targets for external platforms.
  • Multi-User Account Systems - Supports multi-user accounts with role-based access for collaborative certificate management.
  • Cloud Platform Plugins - Ships a plugin system for adding new cloud platforms with access, DNS, and deploy modules.

Istoric stele

Graficul istoricului de stele pentru certd/certdGraficul istoricului de stele pentru certd/certd

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Alternative open-source pentru Certd

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu Certd.
  • allinssl/allinsslAvatar allinssl

    allinssl/allinssl

    3,359Vezi pe GitHub↗

    Allinssl is a multi-platform certificate manager and ACME automator designed to handle the full lifecycle of security certificates. It provides a web-based management interface to orchestrate the issuance, renewal, and deployment of certificates across various servers and cloud environments. The system distinguishes itself through an orchestration engine that pushes certificates to diverse targets, including web application firewalls, server control panels, and remote hosts. It automates domain ownership verification using DNS challenges across multiple providers and employs an event-driven w

    TypeScriptacmeautomationgo
    Vezi pe GitHub↗3,359
  • neilpang/acme.shAvatar Neilpang

    Neilpang/acme.sh

    46,922Vezi pe GitHub↗

    acme.sh is a shell-based certificate manager and ACME SSL certificate client. It automates the issuance, renewal, and installation of digital security certificates using a portable Unix shell script to remove dependencies on heavy runtime environments. The project specializes in automated domain ownership verification through a DNS challenge automator that integrates with provider APIs. It supports the generation of diverse certificate types, including wildcard certificates and issuance based on pre-existing certificate signing requests. The tool covers the full certificate lifecycle, includ

    Shell
    Vezi pe GitHub↗46,922
  • caddyserver/certmagicAvatar caddyserver

    caddyserver/certmagic

    5,568Vezi pe GitHub↗

    Certmagic is a Go library for automating the issuance and renewal of TLS certificates. It functions as an automatic HTTPS provisioner and ACME client that handles the full lifecycle of certificates to ensure secure connectivity without manual intervention. The library is distinguished by its support for on-demand TLS provisioning, which generates certificates dynamically during the TLS handshake based on the server name. It also provides automation for wildcard certificates through DNS challenge verification and integrates with the ZeroSSL API for certificate acquisition. The project covers

    Goacmeautomatic-httpsgo
    Vezi pe GitHub↗5,568
  • go-acme/legoAvatar go-acme

    go-acme/lego

    9,689Vezi pe GitHub↗

    Lego is an ACME certificate manager and lifecycle tool used to automate the request, renewal, and revocation of SSL and TLS certificates. It implements the ACME protocol to communicate with compliant certificate authorities and manages the full issuance process, including account registration and private key rollovers. The project distinguishes itself through extensive DNS automation, utilizing a provider-based abstraction to solve DNS-01 challenges across various third-party DNS providers. It supports advanced verification workflows such as CNAME-based challenge delegation, DNS zone discover

    Goacmeacme-clientcertificate
    Vezi pe GitHub↗9,689
Vezi toate cele 30 alternative pentru Certd→

Întrebări frecvente

Ce face certd/certd?

Certd is a self-hosted platform that automates the full lifecycle of SSL certificates using the ACME protocol. It handles certificate application, renewal, and deployment across multiple domains through a pipeline-driven workflow engine, with DNS challenge orchestration and multi-cloud deployment capabilities.

Care sunt principalele funcționalități ale certd/certd?

Principalele funcționalități ale certd/certd sunt: ACME Certificate Provisioners, Certificate Lifecycle Management, Visual Workflow Automators, Certificate Lifecycle Pipelines, Configurable Stage Pipelines, Cross-Cloud Certificate Deployment, Cloud Platform Deployments, ACME Clients.

Care sunt câteva alternative open-source pentru certd/certd?

Alternativele open-source pentru certd/certd includ: allinssl/allinssl — Allinssl is a multi-platform certificate manager and ACME automator designed to handle the full lifecycle of security… neilpang/acme.sh — acme.sh is a shell-based certificate manager and ACME SSL certificate client. It automates the issuance, renewal, and… caddyserver/certmagic — Certmagic is a Go library for automating the issuance and renewal of TLS certificates. It functions as an automatic… go-acme/lego — Lego is an ACME certificate manager and lifecycle tool used to automate the request, renewal, and revocation of SSL… win-acme/win-acme — Automate SSL/TLS certificates on Windows with ease. dehydrated-io/dehydrated — Dehydrated is a shell-script ACME client that automates the lifecycle of TLS certificates from certificate authorities…