Certificate Service

The certificate service: TLS certificates, issued by a cloud provider and validated with DNS.

The platform uses CertificateService, through smarter.apps.infrastructure.services.infrastructure .certificates, and the provider’s certificate authority is an implementation of it, e.g. ACMCertificateService.

A certificate is validated with DNS records, which the service creates with a DNSService, normally its provider’s, so that a certificate authority and a DNS service of different providers can be combined.

class smarter.apps.infrastructure.services.certificates.Certificate(id, domain_name, status, validation_records=<factory>)[source]

Bases: object

A TLS certificate, for a domain and its subdomains.

__init__(id, domain_name, status, validation_records=<factory>)
domain_name: str

The certificate’s domain, e.g. example.com.

id: str

The provider’s id of the certificate, e.g. an AWS ACM certificate ARN.

property is_issued: bool
status: str

See CertificateStatus.

validation_records: list[DNSRecord]

The DNS records that prove control of the domain, once the provider has generated them.

class smarter.apps.infrastructure.services.certificates.CertificateService(provider_name, dns, *args, **kwargs)[source]

Bases: InfrastructureService

The TLS certificate service of a cloud provider.

Parameters:
  • provider_name (str) – The name of the provider, e.g. aws.

  • dns (DNSService) – The DNS service in which to create validation records.

__init__(provider_name, dns, *args, **kwargs)[source]
billable_certificates: bool = False

Whether the provider bills for certificates.

AWS ACM’s public certificates are free.

certificate_status(certificate_id)[source]

Return a certificate’s status, e.g. PENDING_VALIDATION or ISSUED.

See CertificateStatus.

Return type:

str

create_validation_records(certificate_id)[source]

Create the DNS records that validate a certificate, in its domain’s zone.

The zone is created if it does not exist. The provider can only read the records once the domain is delegated to the zone.

Parameters:

certificate_id (str) – The provider’s id of the certificate.

Return type:

list[DNSRecord]

Returns:

The validation records.

delete_certificate(certificate_id)[source]

Delete a certificate.

Parameters:

certificate_id (str) – The provider’s id of the certificate.

Return type:

bool

Returns:

True if it was deleted, False if it did not exist.

error_class

alias of CertificateServiceError

get_certificate(certificate_id)[source]

Return a certificate.

Parameters:

certificate_id (str) – The provider’s id of the certificate.

Raises:

CertificateNotFound – If the certificate does not exist.

Return type:

Certificate

get_certificate_id(domain_name)[source]

Return the id of a domain’s certificate.

Parameters:

domain_name (str) – The certificate’s domain, e.g. example.com.

Return type:

Optional[str]

Returns:

The id, or None if the domain has no certificate.

get_or_create_certificate(domain_name)[source]

Return the id of a domain’s certificate, and request one if it has none.

The certificate covers the domain and its subdomains, e.g. example.com and *.example.com. It is not issued until its validation records exist, see create_validation_records().

Parameters:

domain_name (str) – The certificate’s domain.

Return type:

tuple[str, bool]

Returns:

The certificate’s id, and whether it was requested.

is_issued(certificate_id)[source]

Whether a certificate is issued, i.e. its domain is validated.

Return type:

bool

issue_wait_attempts: int = 20

How many times wait_until_issued() checks the certificate.

issue_wait_seconds: float = 30

Seconds between the checks.

service_name: str = 'certificates'

The name of the service in signals and logs, see InfrastructureServiceNames.

validation_wait_attempts: int = 120

How many times to look for a new certificate’s validation records, before CertificateTimeout.

validation_wait_seconds: float = 5

Seconds between the attempts.

A provider generates validation records in seconds.

wait_for_validation_records(certificate_id)[source]

Return a certificate once its provider has generated its validation records.

Parameters:

certificate_id (str) – The provider’s id of the certificate.

Raises:
Return type:

Certificate

wait_until_issued(certificate_id)[source]

Wait for a certificate to be issued.

Parameters:

certificate_id (str) – The provider’s id of the certificate.

Return type:

bool

Returns:

True if it is issued, False if it is not after issue_wait_attempts checks.