Skip to content
@certkit-io

CertKit

Centralized Certificate Management that automates the discovery, lifecycle, distribution, and monitoring of your SSL Certificates.

CertKit

Certificate management for people with better things to do.

The Problem

Certificate lifetimes are getting shorter. The 200-day mandate started March 15, 2026. By 2027, we're looking at 47 days. Manual renewal isn't a strategy anymore.

Your options today:

  • CertBot - Works great for one server, until you stop paying attention and it breaks.
  • Cert Manager - Perfect if your entire world is Kubernetes and YAML is your love language.
  • DigiCert/Sectigo - Starting at $call-us-so-we-can-upsell-you per year.
  • That bash script Terry wrote - Terry left in 2019. Nobody knows how it works.

What We Built

CertKit handles the entire certificate lifecycle so you don't have to:

Automatic discovery - Finds all your issued certificates, even that Jenkins box from 2018
Multi-environment deployment - Linux, Windows, F5, Palo Alto, Citrix, that server under Bob's desk
DNS validation without the nightmare - One CNAME record for _acme-challenge, that's it. We never touch the rest of your DNS.
Alerts where you actually look - Slack, Teams, email, wherever
A dashboard that doesn't suck - See what's expiring without SSH-ing into 12 servers

Who This Is For

SysAdmins and security teams who are tired of:

  • Certificate expiration fire drills
  • Maintaining homegrown renewal infrastructure
  • Explaining to management why the cert expired (again)
  • Paying enterprise prices for basic automation

Get Started

Start your free 90-day trial and stop thinking about certificates.

The Team

Built by the TrackJS team. We've been running production infrastructure since 2013. We got tired of certificate management, so we fixed it.

Questions?


Because your time is better spent on literally anything else than certificate management.

Popular repositories Loading

  1. certificate-provisioning certificate-provisioning Public

    Examples and recipes for retrieving certificates from CertKit and applying them to your hosts.

    Shell 7 1

  2. certkit-agent certkit-agent Public

    CertKit Agents run directly on your hosts and manage the full certificate lifecycle (registration through renewal and deployment)

    Go 5 1

  3. certkit-keystore certkit-keystore Public

    Store your private keys on your own infrastructure

    Go 3

  4. ansible-role-sync ansible-role-sync Public

    Ansible role for installing the certkit certificate sync script. Used to deploy certificates managed by Certkit.io.

    Shell

  5. .github .github Public

    CertKit GitHub profile readme

  6. ansible-role-agent ansible-role-agent Public

    Ansible role for installing the certkit-agent. Used to deploy certificates managed by Certkit.io.

Repositories

Showing 7 of 7 repositories

Top languages

Loading…

Most used topics

Loading…