Wood Chen

certimate: Automated Wildcard Certificates and Deployment to BT Panel, 1panel, edgeone, and More

0 comments352 views570 words

This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文

Project URL: https://github.com/usual2970/certimate Original post: https://www.q58.club/t/topic/347

Backend: GO, database: sqlite, frontend: react+ant-design

Original project description: An open-source SSL certificate management tool that helps you automatically request and deploy SSL certificates, and renew them before they expire. An open-source SSL certificate management tool that helps you automatically apply for and deploy SSL certificates, as well as automatically renew them when they are about to expire.

Supported Domain Providers

https://docs.certimate.me/docs/reference/providers/#supported-host-providers

Supported Platforms

https://docs.certimate.me/docs/reference/providers/#supported-dns-providers

I mainly use it because it supports edgeone and 1panel.

For more details, see the project's readme. Here, I'll briefly explain how I use it.

My Installation Method

Author's documentation: https://docs.certimate.me/docs/getting-started/installation/docker

I installed it with docker on a VPS outside China because I use google certificates. If you use another certificate provider, the location doesn't matter—you can use a VPS in China or even deploy it on a Synology NAS.

services:
  certimate:
    image: woodchen/certimate:latest # I use my own docker build, with no real changes. The original author's docker image is: usual2970/certimate:latest
    container_name: certimate
    ports:
      - 1009:8090
    volumes:
      - ./data:/app/pb_data
    restart: unless-stopped

Pasted image 20250311221241

Then set up a reverse proxy for the port, and you can access it.

Default Credentials—Remember to Change Them. I Changed the Username First, Then the Password

  • Username: admin@certimate.fun
  • Password: 1234567890 Pasted image 20250311221129

Pasted image 20250311221149

The Certificate Authority I Use

google

Pasted image 20250311222539

Pasted image 20250311222555

Other options

Pasted image 20250311222624

Pasted image 20250311222648

The author has been very thorough: every section includes explanations and links to official documentation 👍

My DNS Providers and Deployment Platforms

DNS: cloudflare + dnspod

Pasted image 20250311221336

Pasted image 20250311221358

Deployment Platforms: 1panel on Multiple VPS Instances + edgeone

edgeone uses the same authorization method as DNS.

1panel takes a little more work. You need to enable its API here:

Pasted image 20250311221654

Then add it in certimate like this:

Pasted image 20250311221830

One Thing to Note

If certimate and 1panel are on the same server, you need to add the docker container's IP to the 1panel API allowlist, not the server's IP. Here's my setup:

Pasted image 20250311222027

This corresponds to:

Pasted image 20250311222131

Editing the Workflow

This should be fairly straightforward. Create a new workflow, roughly like mine:

Pasted image 20250311222341

I set this to 10 days. Since it checks once a week, there's no need to renew until fewer than 10 days remain.

Pasted image 20250311222407

Pasted image 20250311222818

If anything is unclear, hover over the question mark. The author has provided documentation links and explanations.

Pasted image 20250311222906

If You Can't Find the Website ID in 1panel, See My Screenshots Below

Pasted image 20250311223001

Pasted image 20250311223039

This is the website ID: 90

Pasted image 20250311223153

You can run steps in parallel or sequentially, depending on your preference. I use a Feishu bot for notifications, but other notification platforms are supported too:

Pasted image 20250311223300

Running the Workflow

Once you've finished editing the workflow, click Publish Changes and Enable.

Pasted image 20250311223451

You can run it manually and check the logs for any issues.

Pasted image 20250311223529

Pasted image 20250311223543

Pasted image 20250311223625


If anything else is unclear, check the author's documentation site: https://docs.certimate.me/

It's very detailed and pretty much spot-on. I took a quick look at the code; it mostly uses the official SDK rather than a hand-rolled implementation, which should make future updates easy too.

It's handy for personal use, but if you want to turn it into a paid SaaS offering, there probably isn't much of a market. People are already getting certificates for free, so they generally won't pay for this. You also need to consider issues like someone having you send requests to their server, exposing your own server's IP address.

Related posts

Comments 0