Self-hosted certificate control

One vault for every TLS certificate.

Issue, renew, protect, and distribute certificates across your homelab from one focused control plane.

DNS-01 automation Encrypted at rest Scoped client access
01

Automated issuance

Obtain wildcard and multi-domain certificates through any DNS provider supported by lego.

02

Protected material

Keep ACME account keys and certificate private keys authenticated-encrypted at rest.

03

Controlled delivery

Give clients only the operations and certificate artifacts they are explicitly allowed to use.

Operational clarity

See certificate health at a glance.

The responsive console brings validity, renewal activity, version history, ACME accounts, API keys, and audit events into one place.

Explore operations →
CertVault certificate inventory dashboard
Simple by design

A focused control plane for your homelab.

DNS provider ── DNS-01 ──> CertVault ── encrypted versions ──> persistent volume
                              ├── web console for administrators
                              └── scoped HTTPS API for certificate consumers

Warning

CertVault can return private keys. Do not expose it over plaintext HTTP outside a trusted local development environment.