Metadata-Version: 2.4
Name: certlord
Version: 1.0.0rc1
Summary: TLS certificate lifecycle automation
Home-page: https://github.com/decryptus/certlord
Author: Adrien Delle Cave
Author-email: pypi@doowan.net
License: License GPL-3
Classifier: Development Status :: 4 - Beta
Classifier: License :: OSI Approved :: GNU General Public License v3 (GPLv3)
Classifier: Natural Language :: English
Classifier: Operating System :: Unix
Classifier: Programming Language :: Python
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: System :: Monitoring
Classifier: Topic :: Utilities
Requires-Python: >=3.11
Description-Content-Type: text/markdown
License-File: LICENSE
Requires-Dist: certbot-httpreq>=0.0.24
Requires-Dist: dnspython==1.16.0
Requires-Dist: dwho>=0.3.63
Requires-Dist: httpdis>=0.6.33
Requires-Dist: hvac>=2.4.0
Requires-Dist: pycurl>=7.48.0
Requires-Dist: pyOpenSSL>=26.1.0
Requires-Dist: PyYAML>=6.0.3
Requires-Dist: requests>=2.34.2
Requires-Dist: six>=1.17.0
Requires-Dist: sonicprobe>=0.3.56
Requires-Dist: statuscake>=1.4.5
Requires-Dist: updownio>=0.1.0
Requires-Dist: redis>=4.5.5
Dynamic: author
Dynamic: author-email
Dynamic: classifier
Dynamic: description
Dynamic: description-content-type
Dynamic: home-page
Dynamic: license
Dynamic: license-file
Dynamic: requires-dist
Dynamic: requires-python
Dynamic: summary

<p align="center">
  <picture>
    <source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/decryptus/certlord/v1.0.0rc1/assets/brand/svg/logo-horizontal-dark.svg">
    <img src="https://raw.githubusercontent.com/decryptus/certlord/v1.0.0rc1/assets/brand/svg/logo-horizontal.svg" alt="CertLord" width="520">
  </picture>
</p>

# CertLord

TLS certificate lifecycle automation.

Version: **1.0.0rc1 — release candidate**. See the [release notes](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/release-notes.md).

CertLord coordinates certificate creation and renewal through Certbot, external
PEM import and version-checked replacement, Redis-backed HTTP challenges, Vault
storage and deployment through Auton. Optional destination TLS verification checks
the certificate actually served before acknowledgement. StatusCake/Updown adapters
are optional; expiry observations are exposed for an external supervision system.
It uses DWho, HTTPdis and Sonicprobe.

## Names and installation

- Python distribution and package: `certlord`
- Command and system service: `certlord`
- Default configuration: `/etc/certlord/certlord.yml`
- Service user and group: `certlord`

Requires Python 3.11+ on POSIX; CI validates Python 3.11 and 3.12.
Newer interpreters are not yet validated. Install the Python package with `python -m pip install .`.
System configuration and external services must also be provisioned. The
Debian 12 package includes an isolated Python environment and the service account;
follow the installation guide before enabling the service.
Repository: https://github.com/decryptus/certlord.
This candidate is intended for evaluation; production acceptance remains deployment-specific.

See [MIGRATION.md](https://github.com/decryptus/certlord/blob/v1.0.0rc1/MIGRATION.md) before updating an existing installation.

## Project documentation

- [Certificate UUIDs, HTTP API, CLI and TUI](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/certificate-identity.md)
- [Architecture and behavior](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/architecture.md)
- [Component contracts and compatibility](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/components.md)
- [Tests and staging checklist](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/testing.md)
- [ACME HTTP Connector integration](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/acme-connector.md)
- [Debian 12 installation and isolated dependencies](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/debian-installation.md)
- [External certificate import and replacement](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/certificate-import.md)
- [Operations and recovery](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/operations.md)
- [Operation correlation and optional Auton receipts](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/operation-correlation.md)
- [Coding conventions and contributions](https://github.com/decryptus/certlord/blob/v1.0.0rc1/CONTRIBUTING.md)
- [Brand assets](https://github.com/decryptus/certlord/blob/v1.0.0rc1/assets/brand/README.md)

## Development checks

Run both suites with the runtime dependencies installed:

```sh
python -m pip install -r requirements.txt
python .github/scripts/check-test-collection.py --runner unittest tests tests/contracts
python -m unittest discover -s tests -v
python -m unittest discover -s tests/contracts -v
```

Build a source archive and a wheel in an isolated build environment:

```sh
python -m pip install build
python -m build
```

Build dependencies (including PyYAML, needed to read `setup.yml`) are declared
in `pyproject.toml`. Direct dependency floors match the tested baseline in `constraints-minimum.txt`.
CI exercises both that baseline and the latest resolvable dependencies.
Versioned releases publish to PyPI after the test, lifecycle and package checks.
Debian packaging targets Debian 12 / Python 3.11 on amd64. See the
[installation guide](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/debian-installation.md) and validation instructions in
[testing](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/testing.md). Installed-unit start/stop/restart is checked under
disposable systemd PID 1. Controlled stop/restart during issuance and deployment is also verified through
the installed unit. Historical upgrades, host reboot and other distributions
remain separate gates.

Guide: [Certificate observations and supervision](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/supervision.md).

[Post-deployment TLS verification](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/tls-verification.md) checks configured destinations before acknowledgement.

[Operations and recovery](https://github.com/decryptus/certlord/blob/v1.0.0rc1/docs/operations.md): health, queues, retries and first-version limits.
