Skip to content
Almanac

Oarlock

Your own certificate authority for internal TLS everywhere

Logged
04 OCT 2025
Outbound
348
Bearing
example.com

Oarlock runs a private certificate authority with sane defaults: issue certificates for internal services, automate renewal, and get honest TLS on names that never face the internet.

Worth knowing before you commit:

  • Distributing the root to your devices is the one-time chore.
  • Short-lived certificates plus automation beat long-lived ones.
  • Integrates with the common proxies for automatic issuance.

Internal traffic deserves real certificates too. This makes it painless.

Nearby in Auth & Security

Lockship

1.8k ↗

Self-hosted identity provider: SSO, MFA and user lifecycle in one place

Auth & SecurityDockerSSO

Gatelatch

1.2k ↗

Login portal and 2FA gate for apps that never had accounts

Auth & SecurityDockerProxy