Sign inSign up

memanes688/cert-exp-checker

By memanes688

•Updated about 2 months ago

Lightweight zero-config SSL/TLS certificate expiry checker with automated email alerts.

Image
Security
Developer tools
Monitoring & observability
0

201

memanes688/cert-exp-checker repository overview

⁠🔒 Docker SSL Certificate Expiry Checker

A lightweight, standalone Docker tool to monitor SSL/TLS certificate expiration dates for target domains and automatically send email alerts when certificates are nearing expiration or expired.

Docker Hub Image: memanes688/cert-exp-checker:latest⁠


⁠✨ Key Features

  • ✉️ Built-in Postfix MTA: Includes an internal Postfix mail daemon inside the container. No external mail server or host dependencies required on cloud VMs!
  • 🐳 Docker Ready: Run anywhere with Docker CLI or Docker Compose in seconds.
  • 🎯 Flexible Domain Setup: Pass domains via the DOMAINS environment variable or volume-mount a domains.txt file.
  • ⏰ Daemon & One-Shot Modes: Run continuously as a background daemon (checking every N hours) or run on-demand/via cron.
  • 📧 HTML Status Reports: Color-coded, responsive email tables displaying domain health, remaining days, and issuing CA.
  • 🛠️ Optional Custom SMTP: Supports Gmail, Office 365, SendGrid, AWS SES, or custom SMTP relays.

⁠🚀 Deployment Options

⁠Option 1: Zero-Config Cloud Run (Azure / AWS / GCP / Linux VM)

Cloud instances have public PTR/DNS records. The container uses its internal Postfix MTA to send alerts directly:

docker run --rm \
  -e EMAIL_TO="[email protected]" \
  -e DOMAINS="example.com, google.com, github.com" \
  -e ONESHOT=true \
  memanes688/cert-exp-checker:latest
⁠Option 2: Workstation Run (Using Gmail / Outlook / Custom SMTP)

For local workstations or home IP networks, pass SMTP credentials to bypass ISP Port 25 blocking:

docker run --rm \
  -e EMAIL_TO="[email protected]" \
  -e DOMAINS="example.com, google.com" \
  -e SMTP_HOST="smtp.gmail.com" \
  -e SMTP_PORT=587 \
  -e SMTP_USER="[email protected]" \
  -e SMTP_PASS="YOUR_16_CHAR_APP_PASSWORD" \
  -e ONESHOT=true \
  memanes688/cert-exp-checker:latest
⁠Option 3: Docker Compose (Background Daemon Mode)
version: '3.8'

services:
  cert-exp-checker:
    image: memanes688/cert-exp-checker:latest
    container_name: cert_exp_checker
    restart: unless-stopped
    environment:
      - [email protected]
      - DOMAINS=example.com, google.com, github.com
      - ALERT_THRESHOLD_DAYS=30
      - CHECK_INTERVAL_HOURS=24
    volumes:
      - ./config/domains.txt:/app/config/domains.txt:ro

Run in background:

docker compose up -d

⁠⚙️ Environment Variables

VariableRequiredDefaultDescription
EMAIL_TOYesNoneRecipient email address for expiration alerts
DOMAINSNoNoneComma-separated list of target domains (e.g. example.com, api.site.org:8443)
DOMAINS_FILENoconfig/domains.txtPath to file containing target domains (one per line)
ALERT_THRESHOLD_DAYSNo30Trigger email alerts if cert expires in $\le N$ days
CHECK_INTERVAL_HOURSNo24Hours between automated checks in daemon mode
ONESHOTNofalseSet to true to execute check once and exit immediately
EMAIL_FROMNocert-alerts@<host>Sender email header
SMTP_HOSTNoInternal PostfixCustom SMTP server hostname (e.g., smtp.gmail.com)
SMTP_PORTNo25 (587 if host set)Custom SMTP server port
SMTP_USERNoEmptyCustom SMTP username
SMTP_PASSNoEmptyCustom SMTP password
SMTP_USE_TLSNotrueEnable TLS for custom SMTP

⁠📁 Monitored Domains File (config/domains.txt)

You can create a config/domains.txt file and mount it to /app/config/domains.txt:

# Monitored Domains List
example.com
google.com
github.com
mywebsite.org:8443

Tag summary

Content type

Image

Digest

sha256:f80515998…

Size

86.6 MB

Last updated

about 2 months ago

docker pull memanes688/cert-exp-checker