Skip to content

About

Rust certificate lifecycle service with ACME, durable reconciliation, and HTTP-01/DNS-01 orchestration

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

apollo-certd

Repository · MIT license · Contributing · Security

Standalone Rust certificate lifecycle service. It has its own Cargo workspace and versioned certd-protocol crate, with no sibling Apollo implementation dependency. It uses instant-acme for RFC 8555, OpenSSL for keys, CSRs and certificate verification, and SQLite FULL synchronous WAL for intent, account, order, challenge, active-bundle and renewal state.

Configured ACME supports issuance, renewal, leaf-key rotation and revocation. HTTP-01 is served by a bounded local HTTP listener; deploy it on the public challenge path. DNS-01 calls dnsd protocol v1 through a Unix socket. Provider credentials and implementations stay in dnsd. Automatic renewal is scheduled 30 days before expiry, with an interval capped at half the remaining lifetime for short-lived certificates. inspect exposes active bundle expiry. Failed renewals preserve previous active material; terminal failures require operator attention. Durable challenge cleanup is registered before publication and reconciles after both success and terminal failure, including daemon restart. Cleanup retries are bounded to eight and then retain an operator attention record.

Bundles contain ownership, immutable version, chain/key PEM, actual expiry, SHA-256 of concatenated chain DER and leaf SPKI. PEM fields are base64 in JSON. Private files are fsynced, staged and atomically renamed before active metadata and its renewal schedule are committed together. Gateway activation is a separate control-plane transaction using the gateway's owned protobuf protocol. certd never calls a gateway HTTPS request path.

Example configuration:

socket = "/run/apollo-certd/control.sock"
state = "/var/lib/apollo-certd/state.db"
material_dir = "/var/lib/apollo-certd/material"
max_inflight = 32
[acme]
directory = "https://acme-v02.api.letsencrypt.org/directory"
organization_id = "organization"
project_id = "project"
http_listen = "0.0.0.0:5002"
# dns_socket = "/run/apollo-dnsd/control.sock"
# dns_provider = "cloudflare"
# dns_zone = "example.com"

Run APOLLO_CERTD_CONFIG=/etc/apollo-certd/config.toml apollo-certd. Without ACME configuration only inspect and verified bundle installation are available. State and socket directories are private (0700), keys/state/socket are 0600; the authorized control-plane client must use that OS identity. One daemon owns each state directory through a process lock.

See protocol. Reproduce local checks with cargo test --locked --workspace --all-targets and cargo clippy --locked --workspace --all-targets --all-features -- -D warnings. The Python fixtures in tests/ exercise real daemons against Let’s Encrypt Pebble, including HTTP-01/DNS-01 validation and SIGKILL recovery. Configure the fixture environment variables documented at the top of each script. Rust tests generate their own local material; no private certificate files are distributed.

About

Rust certificate lifecycle service with ACME, durable reconciliation, and HTTP-01/DNS-01 orchestration

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages