Ross ROSS = Recommend OSS · open-source software intelligence for agents

fabriziosalmi/certmate

Self-hosted certificate lifecycle management: issue, renew, discover, inventory and deploy TLS certificates across your infrastructure observed · 2026-08-28

github.com/fabriziosalmi/certmate · homepage · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

81/100

  • Activity 99
  • Release rhythm 86
  • Longevity 31
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 0.0
  • age_days: 435
  • days_rel: 12
  • days_push: 8
  • n_releases_24m: 155

Full methodology

Adoption not part of the score

1404 stars · 109 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

CertMate is a self-hosted certificate lifecycle management platform that issues and renews TLS certificates via ACME/Let's Encrypt across 29 DNS providers, discovers certificates it did not issue, maintains a certificate inventory, and deploys renewed certificates. It includes a private CA for internal names, a tamper-evident audit trail, OIDC/SSO with RBAC, a REST API with Swagger docs, a CLI, and multiple secret storage backends (Vault, AWS Secrets Manager, Azure Key Vault).

Use cases

  • automate ssl certificate issuance and renewal across multiple dns providers
  • self-hosted lets encrypt certificate management with rest api
  • discover and inventory tls certificates across my infrastructure
  • run a private certificate authority for internal domain names
  • deploy renewed certificates automatically to servers
  • centralized certificate expiry monitoring and audit trail
  • manage acme dns-01 challenges for cloudflare route53 azure dns

When to choose

  • you need centralized, self-hosted TLS certificate lifecycle management with an API and CLI
  • you want certificate discovery and inventory across a multi-provider DNS estate
  • you need a private CA for internal names alongside public ACME certificates
  • compliance requirements (e.g., NIS2) demand a tamper-evident audit trail and RBAC/SSO

When to avoid

  • you only manage one or two certificates where a simple certbot/caddy setup suffices
  • you need a GUI-first certificate manager rather than an API-centric service
  • you cannot run a persistent self-hosted service or Docker container

Facets

service · maturity active

security workflow-automation api-framework http-server secrets-management monitoring cli self-hosted security self-hosted networking apis self-hosted python cli tls ssl acme lets-encrypt certificate-lifecycle-management private-ca dns-01 certificate-inventory certificate-discovery mtls oidc rbac audit-trail rest-api nis2 devops automation docker linux web-server

10 sources

Member repositories

RepositoryRoleHealth v2
fabriziosalmi/certmatemain81

For agents

markdown · JSON · MCP: product_card(name="fabriziosalmi/certmate")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem