Scheduled pull
clmbot connects outbound to the upstream service and requires no inbound port, making it suitable for private networks and strict firewalls.
Certificate delivery infrastructure
clmbot securely delivers and deploys SSL/TLS certificates across servers and private environments.
clmbot runs in a customer-controlled environment and connects an upstream certificate service to servers, middleware, and certificate directories. It can connect to CaaS and continue adapting to private CLM or other certificate services.
Compare the two operating modesclmbot connects outbound to the upstream service and requires no inbound port, making it suitable for private networks and strict firewalls.
The upstream service pushes over mTLS through a controlled inbound port, for centrally managed, near-real-time delivery.
Turn manual certificate copying, path changes, and service reloads into a configured, logged, repeatable workflow.
Scan certificate files and deployment paths on a server, then generate a configuration you can inspect and maintain.
Connect to CaaS, a private CLM, or another certificate service through an available adapter.
Back up existing files before writing new certificates and restrict file permissions to the minimum required.
Run reviewed before_script and after_script commands to validate configuration and reload the target service.
Use scheduled pull or remote push to make certificate updates repeatable.
Server deployment and cloud-product API delivery are different paths. The platform catalog keeps these target types separate.
For physical servers, virtual machines, containers, Kubernetes, and customer-managed web services.
CaaS is a separate certificate lifecycle management service that can deliver certificates directly to CDNs, WAFs, load balancers, and similar products through vendor APIs.
Run clmbot under a dedicated system account with access only to required certificate paths and exact reload commands. Scheduled pull requires no inbound port.
Read the least-privilege guideDiscussions and Issues are open for questions, reproducible problems, ideas, and deployment experience. Source code is not currently public; any future open-source release will be announced separately.