Skip to main content

version python_support docker ci coverage

Features

DNSroboCert is designed to manage Let’s Encrypt SSL certificates based on DNS challenges.

  • Let’s Encrypt wildcard and regular certificates generation by Certbot using DNS challenges,

  • Integrated automated renewal of almost expired certificates,

  • Standardized API through Lexicon library to insert the DNS challenge with various DNS providers,

  • Centralized YAML configuration file to maintain several certificates and several DNS providers with configuration validity control,

  • Modification of container configuration without restart,

  • Flexible hooks upon certificate creation/renewal including containers restart, commands in containers or custom hooks,

  • Support for DNS alias mode (see the follow_cnames option in the certificate section),

  • Linux, Mac OS X and Windows support, with a particular care for Docker services,

  • Delivered as a standalone application and a Docker image.

Why use DNSroboCert

If you are reading these lines, you certainly want to secure all your services using Let’s Encrypt SSL certificates, which are free and accepted everywhere.

If you want to secure Web services through HTTPS, there is already plenty of great tools. In the Docker world, one can check Traefik, or nginx-proxy + letsencrypt-nginx-proxy-companion. Basically, theses tools will allow automated and dynamic generation/renewal of SSL certificates, based on TLS or HTTP challenges, on top of a reverse proxy to encrypt everything through HTTPS.

So far so good, but you may fall in one of the following categories:

  1. You are in a firewalled network, and your HTTP/80 and HTTPS/443 ports are not opened to the outside world.

  2. You want to secure non-Web services (like LDAP, IMAP, POP, etc.) were the HTTPS protocol is of no use.

  3. You want to generate a wildcard certificate, valid for any sub-domain of a given domain.

For the first case, ACME servers need to be able to access your website through HTTP (for HTTP challenges) or HTTPS (for TLS challenges) in order to validate the certificate. With a firewall these two challenges - which are widely used in HTTP proxy approaches - will not be usable: you need to ask a DNS challenge. Please note that traefik embed DNS challenges, but only for few DNS providers.

For the second case, there is no website to use TLS or HTTP challenges, and you should ask a DNS challenge. Of course you could create a “fake” website to validate the domain using a HTTP challenge, and reuse the certificate on the “real” service. But it is a workaround, and you have to implement a logic to propagate the certificate, including during its renewal. Indeed, most of the non-Web services will need to be restarted each time the certificate is renewed.

For the last case, the use of a DNS challenge is mandatory. Then the problems concerning certificates propagation that have been discussed in the second case will also occur.

The solution is a dedicated and specialized tool which handles the creation/renewal of Let’s Encrypt certificates, and ensure their propagation in the relevant services. It is the purpose of this project.

Documentation

Online documentation (user guide, configuration reference) is available in the DNSroboCert documentation.

For a quick start, please have a look in particular at the User guide and the Lexicon provider configuration.

Support

Do not hesitate to join the DNSroboCert community on Github Discussions if you need help to use or develop DNSroboCert!

Contributing

If you want to help in the DNSroboCert development, you are welcome! Please have a look at the Developer guide page to know how to start.

Metadata

Release files for dnsrobocert 3.27.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dnsrobocert 3.27.1
File Size Uploaded
dnsrobocert-3.27.1.tar.gz 218.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dnsrobocert 3.27.1
File Interpreter ABI Platform
dnsrobocert-3.27.1-py3-none-any.whl Python 3 none any Details

Total release size: 240.4 kB

Release files / dnsrobocert-3.27.1.tar.gz

Download URL dnsrobocert-3.27.1.tar.gz
Size 218.6 kB
Tags Source
SHA-256 checksum
How to use checksums
2aceadf82e023f8464740c9a00b3c0e36731286cb3792608c418e1f789f38e68
BLAKE2b-256 checksum
How to use checksums
a9e57350bf0736df1f4adc205a34a1982682d3c2952989c88537e9b4ab101234
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.3 {"installer":{"name":"uv","version":"0.12.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / dnsrobocert-3.27.1-py3-none-any.whl

Download URL dnsrobocert-3.27.1-py3-none-any.whl
Size 21.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c40e0cd883e79b6af248a92c6e4bab2f4e78e1f4c1524b5d4b1942e01191fec9
BLAKE2b-256 checksum
How to use checksums
4feec593874c178b6af90bee8fda4f09224b2154b627be4b741111b64782492e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.3 {"installer":{"name":"uv","version":"0.12.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

3.27.1 This release

2 release files

3.27.0

2 release files

3.26.1

2 release files

3.26.0

2 release files

3.25.0

2 release files

3.24.2

2 release files

3.24.1

2 release files

3.23.1

2 release files

3.23.0

2 release files

3.22.1

2 release files

3.22.0

2 release files

3.21.0

2 release files

3.20.1

2 release files

3.18.0

2 release files

3.17.1

2 release files

3.17.0

2 release files

3.15.0

2 release files

3.14.0

2 release files

3.12.0

2 release files

3.11.1

2 release files

3.11.0

2 release files

3.9.1

2 release files

3.9.0

2 release files

3.8.3

2 release files

3.8.2

2 release files

3.8.1

2 release files

3.8.0

2 release files

3.7.5

2 release files

3.7.4

2 release files

3.7.3

2 release files

3.7.2

2 release files

3.7.1

2 release files

3.7.0

2 release files

3.6.0

2 release files

3.5.1

2 release files

3.5.0

2 release files

3.4.0

2 release files

3.3.4

2 release files

3.3.3

2 release files

3.3.2

2 release files

3.3.1

2 release files

3.3.0

2 release files

3.2.0

2 release files

3.1.7

2 release files

3.1.6

2 release files

3.1.5

2 release files

3.1.4

2 release files

3.1.3

2 release files

3.1.2

2 release files

3.1.1

2 release files

3.1.0

2 release files

3.0.2

2 release files

3.0.1

2 release files

3.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page