Job dns-letsencrypt


Skip to build

Let's encrypt DNS provisioning

This is a MirageOS unikernel which provisions TLS certificates using let's encrypt. It looks for certificate signing requests, stored as TLSA records in DNS zones, and uses the let's encrypt ACME DNS challenge to retrieve certificates. The certificate chain is stored in DNS as TLSA record as well. This unikernel also ensures that certificates are valid for at least two weeks.

This can be used with dns-primary-git.

Installation from source

To install this unikernel from source, you need to have opam (>= 2.0.0) and ocaml (>= 4.07.0) installed. Also, mirage is required (>= 3.7.7). Please follow the installation instructions.

The following steps will clone this git repository and compile the unikernel:

$ git clone
$ mirage configure -t <your-favourite-target>
$ make depend
$ make

Installing as binary

There are not yet any binaries available, but work is underway to provide reproducible binaries.


Please open an issue if you have questions, feature requests, or comments.

Build 2021-10-13 11:15:10 -00:00

Back to readme

Build took 12min4s.

Execution result: exited 0.

Reproduced by builds

2021-10-15 11:15:56 -00:00, 2021-10-14 11:15:33 -00:00,

Build info

Comparisons with other builds

With latest build
With build 2021-10-12 11:14:47 -00:00 (output is identical binary)
With build 2021-10-08 11:13:17 -00:00 (output is identical binary)

Build artifacts

SHA256:c7739cc57187e0366f0ff1dd983750c6a262388c9f6a60a54a7c857190329725 (7.98MB)
SHA256:10ba773b16e0779ed62fecb2c18e34dd067eb1fee82cb103aadd6ecfd81ff596 (263B)
SHA256:6bbf8560c687dccf403dba8e297bc66b85ae9445376776765567639ee3462833 (11.7MB)
SHA256:4c672def058f854980f2e9b2e4941d5efa682bca2c4e602674d0a8a915945b7a (230kB)
SHA256:988bcce87c0157b9e31c7dac750f7814f8427a487268ce92dafc549c0b979b28 (184B)