fabriziosalmi/certmate
Self-hosted certificate lifecycle management: issue, renew, discover, inventory and deploy TLS certificates across your infrastructure observed · 2026-08-28
Health v2 · maintenance only
81/100
- Activity 99
- Release rhythm 86
- Longevity 31
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 0.0
- age_days: 435
- days_rel: 12
- days_push: 8
- n_releases_24m: 155
Adoption not part of the score
1404 stars · 109 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
CertMate is a self-hosted certificate lifecycle management platform that issues and renews TLS certificates via ACME/Let's Encrypt across 29 DNS providers, discovers certificates it did not issue, maintains a certificate inventory, and deploys renewed certificates. It includes a private CA for internal names, a tamper-evident audit trail, OIDC/SSO with RBAC, a REST API with Swagger docs, a CLI, and multiple secret storage backends (Vault, AWS Secrets Manager, Azure Key Vault).
Use cases
- automate ssl certificate issuance and renewal across multiple dns providers
- self-hosted lets encrypt certificate management with rest api
- discover and inventory tls certificates across my infrastructure
- run a private certificate authority for internal domain names
- deploy renewed certificates automatically to servers
- centralized certificate expiry monitoring and audit trail
- manage acme dns-01 challenges for cloudflare route53 azure dns
When to choose
- you need centralized, self-hosted TLS certificate lifecycle management with an API and CLI
- you want certificate discovery and inventory across a multi-provider DNS estate
- you need a private CA for internal names alongside public ACME certificates
- compliance requirements (e.g., NIS2) demand a tamper-evident audit trail and RBAC/SSO
When to avoid
- you only manage one or two certificates where a simple certbot/caddy setup suffices
- you need a GUI-first certificate manager rather than an API-centric service
- you cannot run a persistent self-hosted service or Docker container
Facets
service · maturity active
security workflow-automation api-framework http-server secrets-management monitoring cli self-hosted security self-hosted networking apis self-hosted python cli tls ssl acme lets-encrypt certificate-lifecycle-management private-ca dns-01 certificate-inventory certificate-discovery mtls oidc rbac audit-trail rest-api nis2 devops automation docker linux web-server
10 sources
- readme: https://github.com/fabriziosalmi/certmate · fetched 2026-08-28 · a0c7332e2097
- homepage: https://www.certmate.org/ · fetched 2026-08-29 · 849db8242235
- site_page: https://www.certmate.org/docs/index.html · fetched 2026-08-29 · ef75aa11052a
- site_page: https://www.certmate.org/docs/dns-providers.html · fetched 2026-08-29 · 1231e2921e27
- site_page: https://www.certmate.org/docs/api-reference.html · fetched 2026-08-29 · 67c340f80be5
- site_page: https://www.certmate.org/docs/docker-deployment.html · fetched 2026-08-29 · 340bd125e234
- site_page: https://www.certmate.org/docs/storage-backends.html · fetched 2026-08-29 · 15e077e6b61c
- site_page: https://www.certmate.org/docs/backup-recovery.html · fetched 2026-08-29 · 7aa8684b866e
- site_page: https://www.certmate.org/docs/security.html · fetched 2026-08-29 · 5618cb6c7824
- site_page: https://www.certmate.org/docs/troubleshooting.html · fetched 2026-08-29 · f9e676466f49
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| fabriziosalmi/certmate | main | 81 |
For agents
markdown · JSON · MCP: product_card(name="fabriziosalmi/certmate")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem