roundly-consulting / certificates-for-laravel
Manage and provision TLS certificates for your domains from Laravel via pluggable providers.
Package info
github.com/roundly-consulting/certificates-for-laravel
pkg:composer/roundly-consulting/certificates-for-laravel
Fund package maintenance!
Requires
- php: ^8.4
- ext-json: *
- ext-openssl: *
- illuminate/contracts: ^12.0|^13.0
- illuminate/http: ^12.0|^13.0
- illuminate/notifications: ^12.0|^13.0
- illuminate/support: ^12.0|^13.0
- roundly-consulting/alerts-for-laravel: ^1.0
- roundly-consulting/crypto-for-laravel: ^1.0
- roundly-consulting/enums-for-laravel: ^1.0
- roundly-consulting/package-toolkit-for-laravel: ^1.0
Requires (Dev)
- larastan/larastan: ^3.0
- laravel/pint: ^1.18
- nunomaduro/collision: ^8.5
- orchestra/testbench: ^10.0|^11.0
- pestphp/pest: ^4.0
- pestphp/pest-plugin-laravel: ^4.0
- phpstan/extension-installer: ^1.4
- phpstan/phpstan-deprecation-rules: ^2.0
- phpstan/phpstan-phpunit: ^2.0
- roundly-consulting/testing-for-laravel: ^1.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
Certificates for Laravel
Request, track and renew the TLS certificates for your domains directly from Laravel. Issue through Let's Encrypt (a native ACME client), cert-manager on Kubernetes or a filesystem, and keep every certificate's status and expiry in an Eloquent registry you can query, renew and monitor.
Installation
Requires PHP 8.4 (ext-openssl, ext-json) and Laravel 12 or 13.
composer require roundly-consulting/certificates-for-laravel
php artisan vendor:publish --tag="certificates-migrations"
php artisan migrate
If the models you attach certificates to have UUID/ULID keys, set CERTIFICATES_KEY_TYPE
before migrating. Pick the provider with CERTIFICATES_DRIVER: kubernetes (the default),
acme (your app must serve /.well-known/acme-challenge/{token} from the challenge disk) or
filesystem.
Usage
Issue a certificate (one SAN certificate for both hosts) and attach it to its owner:
use RoundlyConsulting\Certificates\Facades\Certificates; $certificate = Certificates::for('shop.example.com') ->alsoFor('www.shop.example.com') ->owner($tenant) // a model using the HasCertificates trait ->issue(); $certificate->status; // CertificateStatus::Issued $certificate->expires_at; // CarbonImmutable $certificate->daysUntilExpiry(); // 90
Keep the registry renewed — schedule the sweep, or drive it yourself:
use Illuminate\Support\Facades\Schedule; Schedule::command('certificates:renew')->daily(); // everything inside renewal.threshold_days Certificates::expiring(14); // Collection<int, Certificate>, soonest first $report = Certificates::renewDue(); // RenewalReport: renewed, queued, failed Certificates::revoke($certificate, 'key compromise');
Documentation
The full documentation — configuration, every feature and its API, and testing — lives on our website: roundly-consulting.com/open-source/docs/certificates-for-laravel
Release notes are in CHANGELOG.md. To contribute, see the contributing guide.
Support our work
This package is free and open source, built and maintained by Roundly Consulting. If it saves you time, please consider supporting our open-source work — a one-time donation, a monthly pledge on Patreon or a crypto donation helps fund maintenance, new features and new packages.
License
The MIT License (MIT). See LICENSE.