sasa1977/site_encrypt
71.1
Strong · 3 October 2026
2.4k
lines of production code
Elixir
primary language
2
measurements over time
What this system is
SiteEncrypt is an Elixir library that automates HTTPS certificate management for web applications by integrating with the ACME protocol. It provides native and Certbot-based clients to handle certificate issuance, renewal, and backup, while offering adapters for Phoenix endpoints to seamlessly inject SSL enforcement. The system supports multiple web server adapters, including Cowboy and Bandit, and includes tools for testing certificate lifecycles in development environments.
How it got here
2018 — Native ACME client migration
8 changes.
The project replaced its internal ACME server and external Certbot dependency with a native Elixir ACME client, consolidating certificate management and verification logic. This overhaul introduced a new configuration schema, automatic certificate backup capabilities, and support for modern Elixir and Phoenix versions.
2020 — ACME protocol and Phoenix integration
9 changes.
This period focused on implementing the core ACME protocol handling, including a native client, local server, and low-level API for certificate management. It also introduced a dedicated Phoenix adapter to integrate these capabilities into web applications, supported by a demo app and comprehensive test coverage for certificate lifecycle and renewal scheduling.
Features
Add Phoenix demo application with SiteEncrypt integration
Introduces a new Phoenix demo application (\PhoenixDemo\) that demonstrates how to integrate the \site\_encrypt\ library for automatic HTTPS certificate management. The demo includes a minimal Phoenix endpoint configuration that uses \SiteEncrypt.Phoenix.Endpoint\ to handle ACME challenges and enforce SSL, with configurable domains, emails, and database folder paths. It also provides a simple 'hello' response to verify the encrypted connection and includes standard project setup files like \.formatter.exs\, \.gitignore\, and a \README.md\ with usage instructions.
demos/phoenix · high confidence
Add SiteEncrypt adapter for Phoenix endpoints
Introduces \SiteEncrypt.Phoenix.Endpoint\ and \SiteEncrypt.Phoenix.Test\ modules to integrate certificate management into Phoenix applications. The endpoint adapter allows developers to replace \use Phoenix.Endpoint\ with \use SiteEncrypt.Phoenix.Endpoint\, automatically injecting ACME challenge handling and certificate lifecycle management while supporting both Cowboy2 and Bandit adapters. A test helper module is also provided to facilitate certification testing using an internal ACME server.
_lib/site\encrypt/phoenix · high confidence
Introduce low-level ACME client API
A new low-level API for interacting with ACME CA servers has been added, providing functions to create sessions, manage accounts, place orders, and handle authorizations and challenges. This module implements the core ACME protocol logic using Mint for HTTP communication, allowing users to invoke these operations from separate processes to avoid blocking. Additionally, a supporting crypto module has been introduced to handle private key generation and Certificate Signing Request (CSR) creation.
_lib/site\encrypt/acme/client · high confidence
Introduce native ACME client and configurable key sizes for certificate management
The certification module now includes a new native ACME client implementation (SiteEncrypt.Certification.Native) alongside the existing Certbot adapter, allowing certificate operations to be performed without relying on the external certbot binary. This change also makes the RSA key size configurable via the config (defaulting to 4096 bits) and introduces randomized renewal scheduling to reduce load on Certificate Authorities. Users benefit from a more robust, dependency-light certificate management path and better control over security parameters.
_lib/site\encrypt/certification · high confidence
New ACME client and local server implementation
This change introduces the core ACME protocol handling for SiteEncrypt, adding a new client module (\SiteEncrypt.Acme.Client\) that automates account creation, domain validation via HTTP-01 challenges, and certificate issuance. It also adds a local ACME server (\SiteEncrypt.Acme.Server\) that can run locally using either Cowboy or Bandit to support development and testing workflows, including DNS resolution and challenge processing.
_lib/site\encrypt/acme · high confidence
Removals
Removal of legacy AcmeServer modules
The \lib/acme\_server\ directory has been cleaned up by removing several internal modules: \Account\, \Crypto\, \Db\, \Jobs\, \JoseJasonAdapter\, \JWS\, \Nonce\, and \Standalone\. These deletions eliminate the previous in-memory ETS-based database, the OpenSSL-dependent certificate signing logic, the custom JWS/JWT handling, and the standalone HTTP server adapter, indicating a consolidation or migration to a different implementation for these capabilities.
_lib/acme\server · high confidence
Removed legacy HTTP verification job implementation and supporting infrastructure
The \AcmeServer.Jobs\ module has been refactored by removing the \HttpVerifier\ GenServer, the \Registry\ for job naming, and the \Supervisor\ that managed job processes. This change eliminates the previous mechanism for handling ACME HTTP-01 verification challenges via a dedicated, dynamically supervised GenServer with retry logic, indicating that this specific verification path is no longer supported or has been replaced by a different implementation elsewhere in the system.
_lib/acme\server/jobs · high confidence
Behavioural changes
Dropped support for Elixir versions prior to 1.16
The library no longer supports Elixir versions older than 1.16. Users must upgrade their Elixir runtime to at least version 1.16 to use this version of the library, as indicated by the new \.tool-versions\ file specifying Elixir 1.19.2 and the changelog entry for version 0.7.0.
(repo-wide) · high confidence
Major configuration schema overhaul and removal of internal ACME server
The library's configuration structure has been significantly reworked: the single \domain\ and \email\ fields are replaced by \domains\ and \emails\ lists, \ca\_url\ is renamed to \directory\_url\ (supporting both external URLs and an internal test server tuple), and new options like \client\ (native vs. certbot), \backup\, \key\_size\, and \mode\ are introduced. Additionally, the internal \AcmeServer\ module, which previously implemented the ACME protocol logic within this library, has been removed entirely, shifting the responsibility of ACME communication to the selected client implementation.
lib · high confidence
Migrate to Config v2 and set test logger level
The application configuration has been updated to use the modern \import Config\ syntax instead of the deprecated \use Mix.Config\, which is required for compatibility with newer Elixir/Phoenix versions. Additionally, the logger level is now explicitly set to \:warning\ when running in the test environment to reduce output noise during testing.
config · high confidence
Phoenix demo now uses Bandit adapter and Jason library
The Phoenix demo configuration has been updated to use the Bandit.PhoenixAdapter instead of the previous default adapter, and explicitly sets Jason as the JSON library. Additionally, logger verbosity is reduced to warning level in the test environment to improve test output clarity.
demos/phoenix/config · high confidence
Refactored ACME server into modular components under new namespace
The ACME server implementation has been reorganized into distinct modules (Account, Challenge, Crypto, Db, JWS, Nonce, and Plug) within the \SiteEncrypt.Acme.Server\ namespace, replacing the previous \AcmeServer\ module structure. This change introduces a dedicated database abstraction using ETS for storing accounts, orders, and nonces, and implements a robust challenge handling process with retry logic and error isolation. Additionally, the cryptographic module now enforces RSA key sizes of at least 2048 bits for CA and server certificates to comply with TLS 1.3 requirements, and the plug has been simplified to streamline request handling.
_lib/site\encrypt/acme/server · high confidence
Refactored certificate management with native ACME client and backup support
The library has replaced the external \certbot\ binary with a native Elixir ACME client (\SiteEncrypt.HttpClient\), removing the \SiteEncrypt.Certbot\ module and its associated file-based challenge logic. This change introduces a new \SiteEncrypt.Adapter\ behavior and a simplified supervision tree that manages ACME servers and certificate renewal jobs internally. Users gain automatic backup and restore capabilities for certificates, improved handling of unknown ACME challenges (returning 404 instead of crashing), and the ability to refresh endpoint configuration dynamically via \SiteEncrypt.refresh\_config/1\. The \SiteEncrypt.Certifier\ and \SiteEncrypt.Phoenix\ modules have been removed in favor of this new, more robust native architecture.
_lib/site\encrypt · high confidence
Test coverage
Added tests for Phoenix demo certificate handling; Added tests for periodic certificate renewal scheduling; Expanded test coverage for certificate lifecycle and configuration changes.
Dependencies
Update dependencies and add Phoenix demo
The main library (site\_encrypt) has been updated to require Elixir 1.16+, switched the parent dependency from a Git repository to Hex (parent 0.12.1), and added optional support for the Bandit web server alongside existing Cowboy support. Development tooling now includes Dialyxir 1.4.7 and ExDoc 0.39.1 for documentation generation. A new Phoenix demo application has been added to demonstrate integration with Phoenix 1.7.11 and Bandit 1.2.1.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 72 → 71 (-0.9)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 91 → 93 (+2.1)
- Maturity 58 → 57 (-1.0)
- Readiness 78 → 75 (-3.5)
- Security 89 → 91 (+2.3)
Resolved (2)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
sasa1977/site_encrypt was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7d8e2e70288a006e601e7def10b0ef2f3fb82f6d — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-8fe32cd45d00.