Keeps an ACME certificate ([tls.acme]) issued and renewed.
At startup, and twice a day, it checks the certificate in
tls.acme.storage. If it is missing, does not cover tls.acme.domains,
or expires within tls.acme.renew_before, a new one is ordered with
Sovite.TLS.ACME:
- An HTTP listener for HTTP-01 challenges starts on
tls.acme.http_address:http_port(port 80 for real CAs: they connect there). It runs only while an order is in progress. - The new key and certificate are written next to each other,
key.pem(mode0600) andcert.pem, then the certificate store reloads them.
A failed attempt is retried after an hour; the current certificate
stays in use meanwhile. The account key is kept in account.key.
Telemetry
[:sovite, :tls, :acme, :issued]-%{},%{domains, not_after}[:sovite, :tls, :acme, :failed]-%{},%{domains, reason}
Summary
Functions
Checks the certificate now, and renews it if needed. Waits for the result.
The certificate and key files ACME maintains for config.
Starts the manager. Options: :config (the [tls.acme] section),
:cert_store, :name, and :acme (extra Sovite.TLS.ACME options,
for tests).
Functions
@spec check(GenServer.server(), timeout()) :: :ok | {:error, term()}
Checks the certificate now, and renews it if needed. Waits for the result.
The certificate and key files ACME maintains for config.
@spec start_link(keyword()) :: GenServer.on_start()
Starts the manager. Options: :config (the [tls.acme] section),
:cert_store, :name, and :acme (extra Sovite.TLS.ACME options,
for tests).