Skip to content

enix/x509-certificate-exporter

Monitoring & Metrics

A Prometheus exporter that monitors X.509 certificate expirations and health across Kubernetes resources (Secrets, ConfigMaps, PKCS#12, JKS, etc.)

Go Latest v4.1.0 · 2mo ago Security brief →

Features

  • Exports certificate expiration metrics from Kubernetes Secrets and ConfigMaps as Prometheus series
  • Supports multiple TLS material sources: PKCS#12 keystores, JKS/JCEKS stores, PEM chains, kubeconfig certs, on‑disk files
  • Tracks CRL freshness and surfaces revocation list staleness alerts
  • Pluggable YAML configuration with a modular architecture for extensibility
  • Runs natively inside Kubernetes clusters or as a standalone binary

Recent releases

View all 7 releases →
No immediate action
v4.1.0 Bug fix

Build metadata preservation

Config change
v4.0.0 Breaking risk
Breaking upgrade

YAML rewrite + breaking changes

No immediate action
v3.21.0 New feature

Images on GHCR

No immediate action
v3.20.1 Bug fix

Server init fix

No immediate action
v3.20.0 New feature

Skip symlinks + label exposure

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
936
Forks
107
Languages
Go Python Mustache

Beta — feedback welcome: [email protected]