This release is a pre-release and may not be stable for production use.
CertLord
TLS certificate lifecycle automation.
Version: 1.0.0rc1 — release candidate. See the release notes.
CertLord coordinates certificate creation and renewal through Certbot, external PEM import and version-checked replacement, Redis-backed HTTP challenges, Vault storage and deployment through Auton. Optional destination TLS verification checks the certificate actually served before acknowledgement. StatusCake/Updown adapters are optional; expiry observations are exposed for an external supervision system. It uses DWho, HTTPdis and Sonicprobe.
Names and installation
- Python distribution and package:
certlord - Command and system service:
certlord - Default configuration:
/etc/certlord/certlord.yml - Service user and group:
certlord
Requires Python 3.11+ on POSIX; CI validates Python 3.11 and 3.12.
Newer interpreters are not yet validated. Install the Python package with python -m pip install ..
System configuration and external services must also be provisioned. The
Debian 12 package includes an isolated Python environment and the service account;
follow the installation guide before enabling the service.
Repository: https://github.com/decryptus/certlord.
This candidate is intended for evaluation; production acceptance remains deployment-specific.
See MIGRATION.md before updating an existing installation.
Project documentation
- Certificate UUIDs, HTTP API, CLI and TUI
- Architecture and behavior
- Component contracts and compatibility
- Tests and staging checklist
- ACME HTTP Connector integration
- Debian 12 installation and isolated dependencies
- External certificate import and replacement
- Operations and recovery
- Operation correlation and optional Auton receipts
- Coding conventions and contributions
- Brand assets
Development checks
Run both suites with the runtime dependencies installed:
python -m pip install -r requirements.txt
python .github/scripts/check-test-collection.py --runner unittest tests tests/contracts
python -m unittest discover -s tests -v
python -m unittest discover -s tests/contracts -v
Build a source archive and a wheel in an isolated build environment:
python -m pip install build
python -m build
Build dependencies (including PyYAML, needed to read setup.yml) are declared
in pyproject.toml. Direct dependency floors match the tested baseline in constraints-minimum.txt.
CI exercises both that baseline and the latest resolvable dependencies.
Versioned releases publish to PyPI after the test, lifecycle and package checks.
Debian packaging targets Debian 12 / Python 3.11 on amd64. See the
installation guide and validation instructions in
testing. Installed-unit start/stop/restart is checked under
disposable systemd PID 1. Controlled stop/restart during issuance and deployment is also verified through
the installed unit. Historical upgrades, host reboot and other distributions
remain separate gates.
Guide: Certificate observations and supervision.
Post-deployment TLS verification checks configured destinations before acknowledgement.
Operations and recovery: health, queues, retries and first-version limits.
Metadata
Release files for certlord 1.0.0rc1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| certlord-1.0.0rc1.tar.gz | 1.2 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| certlord-1.0.0rc1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.3 MB
Release files / certlord-1.0.0rc1.tar.gz
| Download URL | certlord-1.0.0rc1.tar.gz |
|---|---|
| Size | 1.2 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ffcef2ab5c9bda93c4264233ed51faf15f1a1f1832e8f49c3a5bf65b3476d418
|
|
BLAKE2b-256 checksum How to use checksums |
a9eab0e647924809800341f00e362ef3b6771d22dacad197c2932095c0c71c5b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.
Transparency logRelease files / certlord-1.0.0rc1-py3-none-any.whl
| Download URL | certlord-1.0.0rc1-py3-none-any.whl |
|---|---|
| Size | 79.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
283c9d3b0c8f0b44904ffff3f97c7114621271973f4a844ae33ca84a38a23298
|
|
BLAKE2b-256 checksum How to use checksums |
50dd3c2ff219168c24a353b3b097e06594be473c4519341729e9996b7e96800d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.
Transparency log