KrakenKey documentation
KrakenKey issues TLS certificates through ACME DNS-01. You do a one-time DNS setup per domain, and certificates arrive in about four minutes. Your private keys stay with you: KrakenKey only ever sees the certificate signing request.
Start here
Section titled “Start here”- Getting started: add a domain, set up its DNS records, and issue your first certificate.
- How KrakenKey fits your stack: how issuance works, where the private key can live, and which setup matches what you run.
- Set up with an AI agent: point your coding agent at the runbook, do the few steps that need a person, and say go.
- KrakenKey CLI: issue, submit, download and renew certificates from a terminal or CI job.
- API reference: every endpoint in the KrakenKey REST API.
Integrations
Section titled “Integrations”- nginx and HAProxy: issue on the server, point the proxy at the files, and renew with a systemd timer.
- Caddy: load a KrakenKey wildcard with the
tlsdirective for internal hosts, with no DNS credentials on the proxy. - GitHub Actions: issue once, renew on a schedule, and deploy to servers over SSH only when they serve an older certificate.
- AWS Certificate Manager, ALB, and CloudFront: import into ACM, keep the key in Secrets Manager, and re-import each renewal to the same ARN.
- Terraform: register domains, publish their DNS records, issue certificates and set up monitoring in code, without the private key in state.
- Azure Key Vault, App Service, and Container Apps: keep the private key in Key Vault, have KrakenKey sign its CSR, and bind the certificate in App Service or Container Apps.