Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Amazon Web Services
  3. letsencrypt-aws

letsencrypt-aws

BSD-3-ClausePython

Automatically provisions and renews Let's Encrypt SSL certificates for AWS Elastic Load Balancers using Route53 DNS validation.

GitHubGitHub
727 stars119 forks0 contributors

What is letsencrypt-aws?

letsencrypt-aws is a Python-based automation tool that provisions and renews SSL certificates from Let's Encrypt for AWS Elastic Load Balancers. It solves the problem of manual certificate management by automatically handling the entire certificate lifecycle—from DNS validation via Route53 to uploading certificates to IAM and updating ELB configurations.

Target Audience

DevOps engineers and AWS administrators who manage multiple ELBs with SSL certificates and want to automate certificate renewal without manual intervention.

Value Proposition

Developers choose letsencrypt-aws because it provides a lightweight, self-hosted alternative to manual certificate management or paid AWS services, with tight integration to AWS APIs and secure in-memory key handling.

Overview

letsencrypt-aws is a background service that automates SSL certificate management for AWS infrastructure. It continuously monitors Elastic Load Balancers (ELBs) and automatically renews expiring certificates through Let's Encrypt, eliminating manual certificate management overhead.

Key Features

  • Automatic Renewal — Runs daily checks and renews certificates expiring within 45 days
  • AWS Integration — Uses AWS APIs to manage ELBs, IAM certificates, and Route53 DNS records
  • DNS Challenge Validation — Creates Route53 records to complete Let's Encrypt domain validation
  • Secure Key Handling — Generates private keys in memory and uploads directly to IAM without disk storage
  • Docker Support — Available as a pre-built Docker image for easy deployment
  • Persistent Operation — Can run continuously with 24-hour sleep cycles between checks

Philosophy

letsencrypt-aws follows a "set and forget" philosophy, designed to run autonomously in the background while maintaining security best practices for certificate management.

Use Cases

Best For

  • Automating SSL certificate renewal for AWS Elastic Load Balancers
  • Managing Let's Encrypt certificates across multiple domains on AWS
  • Reducing operational overhead for certificate lifecycle management
  • Self-hosting certificate automation without third-party services
  • Integrating Let's Encrypt with AWS Route53 for DNS validation
  • Running certificate automation as a background service on EC2

Not Ideal For

  • Projects already using or planning to adopt AWS Certificate Manager for a fully managed, integrated SSL/TLS solution
  • AWS environments relying on Application Load Balancers (ALBs) or CloudFront, as it only supports Elastic Load Balancers (ELBs)
  • Teams requiring active maintenance, support, and updates for production-critical certificate automation
  • Organizations with strict compliance needs that demand detailed audit logs and monitoring beyond basic IAM integration

Pros & Cons

Pros

Automatic Certificate Renewal

Runs daily checks and renews certificates expiring within 45 days, ensuring continuous SSL/TLS coverage without manual intervention, as described in the loop-based operation.

Tight AWS Integration

Uses AWS APIs to manage ELBs, IAM certificates, and Route53 DNS records, providing seamless automation within the AWS ecosystem, including DNS challenge validation.

Secure Key Management

Generates private keys in memory and uploads them directly to IAM without disk storage, enhancing security by minimizing exposure, as highlighted in the operational security section.

Docker Deployment Support

Available as a pre-built Docker image (alexgaynor/letsencrypt-aws), simplifying deployment and operation in containerized environments, as mentioned in the README.

Persistent Background Operation

Can run continuously with 24-hour sleep cycles using the --persistent flag, making it suitable for long-term, set-and-forget certificate management.

Cons

Poor Maintenance Status

The README explicitly warns that the project is not well maintained, recommending alternatives like AWS Certificate Manager, which poses risks for long-term reliability.

Limited AWS Service Support

Focuses solely on Elastic Load Balancers (ELBs), excluding modern AWS services such as Application Load Balancers (ALBs) or CloudFront, reducing its relevance for updated infrastructure.

Complex Initial Setup

Requires configuring IAM policies, ACME account registration, and JSON environment variables, which can be error-prone and daunting for users without deep AWS expertise.

Frequently Asked Questions

Quick Stats

Stars727
Forks119
Contributors0
Open Issues14
Last commit8 years ago
CreatedSince 2015

Tags

#devops#acme#route53#iam#docker#ssl-certificates#aws#automation#lets-encrypt

Built With

P
Python
D
Docker
b
boto3

Included in

Amazon Web Services14.0k
Auto-fetched 19 hours ago

Related Projects

AlgoAlgo

Set up a personal VPN in the cloud

Stars30,409
Forks2,367
Last commit5 days ago
checkovcheckov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

Stars9,056
Forks1,427
Last commit1 day ago
s2ns2n

An implementation of the TLS/SSL protocols

Stars4,769
Forks805
Last commit1 day ago
security_monkeysecurity_monkey

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.

Stars4,370
Forks777
Last commit5 years ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub