Artisan commands
Six console commands cover the whole lifecycle from the terminal or the scheduler. issue, renew, prune and sync are thin callers of the facade root — Certificates::issue(), renewDue() / renew(), prune() and sync() — so Certificates::fake() records them and --connection targets the chosen registry. check scans with Certificates::expiring(); list is a read-only query of the registry model:
php artisan certificates:issue {domain} {--driver=} {--connection=}
php artisan certificates:list {--driver=} {--status=} {--expiring=} {--connection=}
php artisan certificates:renew {domain?} {--threshold=} {--queue} {--connection=}
php artisan certificates:check {--threshold=} {--alert} {--driver=} {--connection=}
php artisan certificates:prune {--days=30} {--status=} {--connection=}
php artisan certificates:sync {--driver=} {--connection=}| Command | What it does |
|---|---|
certificates:issue | Runs Certificates::issue() for one domain; --driver picks the driver, --connection the registry. Exits non-zero when it fails — an invalid domain, a provider error or a provisioning already in progress. |
certificates:list | Lists registry rows by domain; filter by --driver, --status (a value such as issued), --expiring=N days and --connection. |
certificates:renew | Runs Certificates::renewDue() — or renew() for one domain; --threshold overrides renewal.threshold_days, --queue queues RenewCertificateJob. Prints each outcome and exits non-zero on any failure. |
certificates:check | Scans expiring certificates, fires CertificateExpiring and, with --alert or alerts.enabled, raises health alerts. Never renews. |
certificates:prune | Runs Certificates::prune(): soft-deletes records not updated for --days (default 30) with status expired, failed or revoked — or only --status. |
certificates:sync | Runs Certificates::sync(): pulls the provider’s certificates into the registry by driver and name — with live status, expiry, issuer, serial and fingerprint where reported — and revives pruned rows the provider still reports. |
Examples
php artisan certificates:issue shop.example.com --driver=acme
php artisan certificates:list --status=issued
php artisan certificates:list --expiring=14 --connection=tenant
php artisan certificates:renew --threshold=30 --queue
php artisan certificates:check --threshold=30 --alert
php artisan certificates:prune --days=60 --status=failed
php artisan certificates:sync --driver=kubernetesScheduling
The package registers no schedule. A typical setup renews daily and scans for alerts:
use Illuminate\Support\Facades\Schedule;
Schedule::command('certificates:renew')->daily();
Schedule::command('certificates:check --alert')->daily();Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.