Roadmap
What we're working on and what comes next. Certificate lifetimes drop to 100 days in March 2027, so most of this is about renewals you can schedule and forget, and hearing about problems early.
Updated October 6, 2026. Priorities change; there are no dates here on purpose.
Now
In progress or in review.
Renewal guides for 100-day certificates
Certificate lifetimes drop to 100 days on 2027-03-15. Guides for nginx, Traefik, HAProxy, IIS and Kubernetes: issue with the CLI, renew on a daily timer, write the chain where the server expects it, and reload.
web#86Probe as a system service
Install the probe from the apt and dnf repositories and run it as a systemd service that checks your endpoints on a schedule.
cli#46
Next
Planned after the current work ships.
Kubernetes integration
Request and renew certificates from inside a cluster, with the private key staying in the cluster.
app#124Merkle Tree Certificates
Support for Let's Encrypt's post-quantum certificate format ahead of its 2027 production rollout.
app#125Domain verification that rides out DNS hiccups
The daily recheck retries a failed lookup and allows a grace period, with an alert, before a domain loses its verified status.
Later
On our list, not yet scheduled.
Certificates declared in your repository
List the certificates you need in a file in your GitHub repository. KrakenKey checks pull requests, issues and renews them, and delivers them to repository secrets or a webhook.
API key expiry alerts
A heads-up before an API key expires, through the same email, Slack, Teams and webhook channels as certificate alerts.
Recently shipped
- Terraform provider. Manage domains, certificates, endpoint monitoring and alert channels as Terraform resources. Issue from a CSR without putting the private key in state. Terraform guide
- Signed apt and dnf repositories. Install the CLI from packages.krakenkey.io with apt or dnf and keep it current with normal upgrades. Signed metadata and packages, with key changes delivered by a keyring package. The probe joins with its next release. Install docs
- GitHub Action without a stored key. The certificate action authenticates with GitHub OIDC: trust a repository once, and its workflows get a 15-minute key with that trust policy's scopes and limits. cert-action v1.4.0
- Portfolio TLS report. Check a list of hosts at once for expiry, issuer, hostname coverage and chain problems, sorted by urgency, with a CSV export and a read-only share link. app#123
- ACME Renewal Information (ARI). KrakenKey checks each certificate's CA-suggested renewal window and renews early when the CA asks for a replacement, with an alert when it does. app#121
- Slack, Teams and webhook alerts. Send issuance, renewal, expiry and scan-failure alerts to Slack, Microsoft Teams or your own HTTPS endpoint with signed payloads, alongside email. app#120
- Homebrew and Linux packages for the CLI. brew install krakenkey/tap/krakenkey on macOS and Linux, with updates through brew upgrade, plus .deb and .rpm packages on every release. CLI v0.8.0
- Scoped API keys. Limit a key to what it needs when you create it: read-only, certificate renewal or a custom set of scopes, specific domains or certificates, and the IP addresses it may be used from. app#122
- GitHub Action renewals. An if-due input so scheduled workflows renew only when due, and comma-separated SANs split into separate names. cert-action v1.3.0
- Renewals that are safe to schedule. cert renew --if-due renews only inside your plan's renewal window, so a daily cron job or timer no longer reissues every run. renew --wait now saves the renewed certificate, and a missing chain is reported instead of skipped. CLI v0.7.0
- API key activity and revocation history. See when and from which IP each key was last used. Revoked keys stay visible for 30 days.
- Browser sign-in for the CLI. krakenkey auth login --web approves a CLI session from the dashboard, with no key to copy and paste.
- API keys limited to certificate work. Keys can no longer change account, billing or organization settings, or create more keys. Those need a dashboard session.
- DNS delegation preflight. Missing or wrong _acme-challenge CNAME records fail fast with the exact record to add. September release notes
- Caddy integration guide. Wildcard certificates for Caddy without giving it DNS provider credentials. Guide
Full details are in the monthly release notes and each project's changelog on GitHub.
Missing something you need?
Add a 👍 to the linked issues to tell us what matters to you, or suggest something new in GitHub Discussions. Requests from people running real workloads move items up this page.
Ready to automate your certificates?
KrakenKey automates certificate management so you don't have to.
Get Started FreeFree to use. No credit card required.