Open source
Certificates for Laravel
composer require roundly-consulting/certificates-for-laravelOverview
Request, track and renew the TLS certificates for your domains directly from Laravel. Issue a certificate with one call — from Let’s Encrypt through a native, pure-PHP ACME v2 client, from cert-manager on Kubernetes, or from a Storage disk — and every result lands in a local Eloquent registry with its status, domains, owner and expiry. Renewals, expiry health checks, multi-tenant connections and a recording test fake are built in, all behind one Certificates facade. MIT-licensed and dependency-light: the transport is Laravel’s HTTP client, the CSR is ext-openssl and every cryptographic primitive comes from our audited crypto-for-laravel — no third-party ACME, crypto or Kubernetes SDK.
What you get
Native ACME client
Real certificates from Let’s Encrypt or any ACME v2 CA in pure PHP — HTTP-01 built in, DNS-01 through your own solver.
Pluggable drivers
ACME, Kubernetes cert-manager, a Storage-disk filesystem driver, plus null and in-memory drivers — one API, custom providers welcome.
A queryable registry
Every certificate recorded as an Eloquent model with status, SANs, owner and expiry — “what expires in 14 days?” is one scope.
SAN & wildcard certificates
Cover several hostnames or *.example.com with a single certificate via for([...]) or alsoFor().
Renewals & expiry alerts
Certificates::renewDue() renews or queues everything due and reports each outcome; expiry becomes warning and critical health checks via alerts-for-laravel.
Owners & tenants
Attach certificates to tenants with HasCertificates and target a per-tenant database connection with on().
Facade, DI or actions
Call the Certificates facade, inject CertificatesManager or run an action — and Certificates::fake() records every call with an assertion for each.
Documentation
Installation
Install via Composer, publish and run the registry migrations, pick a driver and optionally publish the config and translations.
Configuration
Every config/certificates.php key with its env var and default — driver, registry, renewal, lock, status cache and alerts.
The Certificates facade
The whole Certificates facade in one place — issuance, renew, revoke and expire, registry-wide renewDue, sync and prune, the for() handle and drivers.
DI and actions
Skip the facade: inject CertificatesManager for the same API, or call the seven single-purpose actions directly from your own code.
Issuing certificates
Issue and track a certificate with one call — issueIfMissing(), issue() with a DTO, generate() — and what happens along the way.
Fluent builder
Certificates::for() is the domain handle — set driver, SANs, owner, meta and validity, then issue, read status, or renew, revoke and expire.
Drivers
The five shipped drivers — kubernetes, acme, filesystem, null and array — what each can do and how to pick one per call.
ACME & Let’s Encrypt
Obtain real certificates from Let’s Encrypt or any ACME v2 CA in pure PHP — HTTP-01 built in, DNS-01 via your own solver.
Kubernetes & cert-manager
Drive cert-manager from Laravel — the kubernetes driver adds TLS hosts to an Ingress and reads Certificate status over the Kubernetes API.
Filesystem driver
Keep PEM material on a Laravel Storage disk — import certificates issued elsewhere or self-sign them for local development.
Multi-domain & wildcards
Cover several hostnames or a wildcard with one SAN certificate, and find the certificate that covers any given host.
The certificate registry
The Eloquent Certificate model — columns, query scopes, expiry helpers, state changes through the facade, a swappable model and the schema.
Status & live reports
The CertificateStatus lifecycle and its transitions, registry status vs. cached live provider reports, and cache control.
Attaching to models
Add HasCertificates to tenants, sites or teams to request, find and list the certificates they own through a certifiable morph.
Multi-tenant connections
Keep each tenant’s registry on its own database connection — per call with on(), app-wide via config, and --connection on commands.
Renewals
Renew certificates nearing expiry with Certificates::renewDue() or certificates:renew — inline or queued, every outcome reported, on your schedule.
Expiry monitoring
Route certificate expiry through alerts-for-laravel — warning and critical bands, per-certificate monitors, certificates:check and lifecycle alerts.
Events
Seven lifecycle events — requested, issued, failed, renewed, expiring, revoked and expired — each carrying the registry model.
Artisan commands
Six commands to issue, list, renew, check, prune and sync certificates — with every option and ready-to-schedule examples.
Extending
Plug in your own certificate provider with Certificates::extend(), persist material through CertificateStore and add macros to the manager.
Validation & errors
Validate domain input with the ValidDomain rule and handle the package’s typed exceptions under one CertificateException base.
Testing
Certificates::fake() records every issue, renewal, revoke, expire, sync and prune in memory, with an assertion for each — plus the array driver.
Requirements
PHP 8.4+ with ext-openssl and ext-json, Laravel 12 or 13, and four Roundly packages pulled in automatically.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.