Sovite.Core.ACME (sovite v0.2.0)

Copy Markdown View Source

Keeps an ACME certificate ([tls.acme]) issued and renewed.

At startup, and twice a day, it checks the certificate in tls.acme.storage. If it is missing, does not cover tls.acme.domains, or expires within tls.acme.renew_before, a new one is ordered with Sovite.TLS.ACME:

  1. An HTTP listener for HTTP-01 challenges starts on tls.acme.http_address:http_port (port 80 for real CAs: they connect there). It runs only while an order is in progress.
  2. The new key and certificate are written next to each other, key.pem (mode 0600) and cert.pem, then the certificate store reloads them.

A failed attempt is retried after an hour; the current certificate stays in use meanwhile. The account key is kept in account.key.

Telemetry

  • [:sovite, :tls, :acme, :issued] - %{}, %{domains, not_after}
  • [:sovite, :tls, :acme, :failed] - %{}, %{domains, reason}

Summary

Functions

Checks the certificate now, and renews it if needed. Waits for the result.

The certificate and key files ACME maintains for config.

Starts the manager. Options: :config (the [tls.acme] section), :cert_store, :name, and :acme (extra Sovite.TLS.ACME options, for tests).

Functions

check(server, timeout \\ 300_000)

@spec check(GenServer.server(), timeout()) :: :ok | {:error, term()}

Checks the certificate now, and renews it if needed. Waits for the result.

files(config)

@spec files(map()) :: %{cert_file: Path.t(), key_file: Path.t()}

The certificate and key files ACME maintains for config.

start_link(opts)

@spec start_link(keyword()) :: GenServer.on_start()

Starts the manager. Options: :config (the [tls.acme] section), :cert_store, :name, and :acme (extra Sovite.TLS.ACME options, for tests).