Certificate Service
The certificate service: TLS certificates, issued by a cloud provider and validated with DNS.
The platform uses CertificateService, through
smarter.apps.infrastructure.services.infrastructure .certificates, and the provider’s
certificate authority is an implementation of it, e.g.
ACMCertificateService.
A certificate is validated with DNS records, which the service creates with a
DNSService, normally its provider’s, so that a
certificate authority and a DNS service of different providers can be combined.
- class smarter.apps.infrastructure.services.certificates.Certificate(id, domain_name, status, validation_records=<factory>)[source]
Bases:
objectA TLS certificate, for a domain and its subdomains.
- __init__(id, domain_name, status, validation_records=<factory>)
- status: str
See
CertificateStatus.
- class smarter.apps.infrastructure.services.certificates.CertificateService(provider_name, dns, *args, **kwargs)[source]
Bases:
InfrastructureServiceThe TLS certificate service of a cloud provider.
- Parameters:
provider_name (
str) – The name of the provider, e.g.aws.dns (
DNSService) – The DNS service in which to create validation records.
- billable_certificates: bool = False
Whether the provider bills for certificates.
AWS ACM’s public certificates are free.
- certificate_status(certificate_id)[source]
Return a certificate’s status, e.g.
PENDING_VALIDATIONorISSUED.See
CertificateStatus.- Return type:
- create_validation_records(certificate_id)[source]
Create the DNS records that validate a certificate, in its domain’s zone.
The zone is created if it does not exist. The provider can only read the records once the domain is delegated to the zone.
- error_class
alias of
CertificateServiceError
- get_certificate(certificate_id)[source]
Return a certificate.
- Parameters:
certificate_id (
str) – The provider’s id of the certificate.- Raises:
CertificateNotFound – If the certificate does not exist.
- Return type:
- get_or_create_certificate(domain_name)[source]
Return the id of a domain’s certificate, and request one if it has none.
The certificate covers the domain and its subdomains, e.g.
example.comand*.example.com. It is not issued until its validation records exist, seecreate_validation_records().
- is_issued(certificate_id)[source]
Whether a certificate is issued, i.e. its domain is validated.
- Return type:
- issue_wait_attempts: int = 20
How many times
wait_until_issued()checks the certificate.
- service_name: str = 'certificates'
The name of the service in signals and logs, see
InfrastructureServiceNames.
- validation_wait_attempts: int = 120
How many times to look for a new certificate’s validation records, before
CertificateTimeout.
- validation_wait_seconds: float = 5
Seconds between the attempts.
A provider generates validation records in seconds.
- wait_for_validation_records(certificate_id)[source]
Return a certificate once its provider has generated its validation records.
- Parameters:
certificate_id (
str) – The provider’s id of the certificate.- Raises:
CertificateTimeout – If the records are not generated in time.
CertificateNotFound – If the certificate does not exist, after the last attempt.
- Return type:
- wait_until_issued(certificate_id)[source]
Wait for a certificate to be issued.
- Parameters:
certificate_id (
str) – The provider’s id of the certificate.- Return type:
- Returns:
True if it is issued, False if it is not after
issue_wait_attemptschecks.