Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

CertLord

CertLord

TLS certificate lifecycle automation.

Version: 1.0.0rc1 — release candidate. See the release notes.

CertLord coordinates certificate creation and renewal through Certbot, external PEM import and version-checked replacement, Redis-backed HTTP challenges, Vault storage and deployment through Auton. Optional destination TLS verification checks the certificate actually served before acknowledgement. StatusCake/Updown adapters are optional; expiry observations are exposed for an external supervision system. It uses DWho, HTTPdis and Sonicprobe.

Names and installation

  • Python distribution and package: certlord
  • Command and system service: certlord
  • Default configuration: /etc/certlord/certlord.yml
  • Service user and group: certlord

Requires Python 3.11+ on POSIX; CI validates Python 3.11 and 3.12. Newer interpreters are not yet validated. Install the Python package with python -m pip install .. System configuration and external services must also be provisioned. The Debian 12 package includes an isolated Python environment and the service account; follow the installation guide before enabling the service. Repository: https://github.com/decryptus/certlord. This candidate is intended for evaluation; production acceptance remains deployment-specific.

See MIGRATION.md before updating an existing installation.

Project documentation

Development checks

Run both suites with the runtime dependencies installed:

python -m pip install -r requirements.txt
python .github/scripts/check-test-collection.py --runner unittest tests tests/contracts
python -m unittest discover -s tests -v
python -m unittest discover -s tests/contracts -v

Build a source archive and a wheel in an isolated build environment:

python -m pip install build
python -m build

Build dependencies (including PyYAML, needed to read setup.yml) are declared in pyproject.toml. Direct dependency floors match the tested baseline in constraints-minimum.txt. CI exercises both that baseline and the latest resolvable dependencies. Versioned releases publish to PyPI after the test, lifecycle and package checks. Debian packaging targets Debian 12 / Python 3.11 on amd64. See the installation guide and validation instructions in testing. Installed-unit start/stop/restart is checked under disposable systemd PID 1. Controlled stop/restart during issuance and deployment is also verified through the installed unit. Historical upgrades, host reboot and other distributions remain separate gates.

Guide: Certificate observations and supervision.

Post-deployment TLS verification checks configured destinations before acknowledgement.

Operations and recovery: health, queues, retries and first-version limits.

Metadata

Release files for certlord 1.0.0rc1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for certlord 1.0.0rc1
File Size Uploaded
certlord-1.0.0rc1.tar.gz 1.2 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for certlord 1.0.0rc1
File Interpreter ABI Platform
certlord-1.0.0rc1-py3-none-any.whl Python 3 none any Details

Total release size: 1.3 MB

Release files / certlord-1.0.0rc1.tar.gz

Download URL certlord-1.0.0rc1.tar.gz
Size 1.2 MB
Tags Source
SHA-256 checksum
How to use checksums
ffcef2ab5c9bda93c4264233ed51faf15f1a1f1832e8f49c3a5bf65b3476d418
BLAKE2b-256 checksum
How to use checksums
a9eab0e647924809800341f00e362ef3b6771d22dacad197c2932095c0c71c5b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release files / certlord-1.0.0rc1-py3-none-any.whl

Download URL certlord-1.0.0rc1-py3-none-any.whl
Size 79.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
283c9d3b0c8f0b44904ffff3f97c7114621271973f4a844ae33ca84a38a23298
BLAKE2b-256 checksum
How to use checksums
50dd3c2ff219168c24a353b3b097e06594be473c4519341729e9996b7e96800d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.0rc1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page