Documentation
Make certificate deployment repeatable.
Start with installation, then configure upstream access, discovery, updates, least privilege, and operations.
Get started
Download, install, initialize, and run your first certificate update.
Configuration and updates
Configure upstream access, discover certificates, and run updates safely.
ConfigurationThe common clmbot configuration model for config.yaml, upstreams, and scripts, plus a CaaS login example.→Certificate discoveryUse discover-certificate to scan a server for existing certificates and generate config.yaml.→Automatic updates and service reloadsUnderstand update-certificate, script review, .bak backups, service reloads, and success, failure, and rollback logs.→
Operating modes
Choose between scheduled pull and remote push.
Operating modesCompare scheduled pull and remote push by connection direction, inbound ports, authentication, update latency, and use case.→Scheduled pullRun update-certificate from Linux crontab or Windows Task Scheduler to automate certificate updates without an inbound port.→Remote pushRun clmbot continuously in Server mode so an upstream can push certificates over mutual TLS, with 8862/TCP and firewall guidance.→
Secure deployment
Reduce system privileges, network exposure, and credential risk.
Least privilegeRun clmbot under a dedicated account with exact sudoers and certificate-directory ACLs for Nginx, Apache, Tomcat, and IIS.→SecurityThe clmbot security model and trust boundaries, including mTLS, credentials, private keys, log sanitization, checksums, firewall rules, and vulnerability reporting.→
Operations and reference
Look up configuration, troubleshoot issues, and maintain deployments.
