reactor-ca: Manage and Deploy Homelab TLS Certificates

Summary
ReactorCA is a Go command-line tool for managing a private CA and issuing TLS certificates for homelab and small-office services. It encrypts private keys with age and can export certificates and run deployment scripts.
At a glance
- Language
- Go
- License
- BSD-2-Clause
- Stars
- 125
- Forks
- 5
- Added to OSRepos
- March 5, 2026
- Last analyzed
- October 3, 2026
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Overview
ReactorCA helps homelab and small-office administrators operate a private Certificate Authority and provide TLS certificates to internal services. It addresses the recurring work of renewing certificates and distributing them to hosts, with a centrally managed store that can be encrypted and kept alongside configuration in Git.
It is best suited to setups where an administrator wants to issue certificates on demand from a desktop or other workstation, rather than run a CA service or automated renewal server. Its workflow manages keys centrally and can run configured deployment commands for target systems.
Key Features
- Create, renew, rekey, import, and inspect a self-signed CA.
- Issue, renew, list, and inspect certificates for configured hosts.
- Encrypt private keys using age with passwords, SSH identities, or age plugins for hardware tokens.
- Export certificates and keys to configured paths, and deploy them using shell scripts.
- Configure X.509 extensions, including name constraints, key usage, and custom OIDs.
- Track certificate status and expiration, with list filters and JSON output.
- Build as a statically linked Go binary without runtime dependencies.
Use Cases
- A homelab administrator issues certificates for LAN services such as dashboards, then deploys them to hosts.
- A small office maintains certificates for internal devices and services without adopting a dedicated CA server.
- An infrastructure Git repository holds CA configuration and an encrypted certificate store, while private keys remain age-encrypted.
- An administrator rotates host keys and renews certificates for multiple devices with a CLI workflow.
Project Facts
- Language: Go
- License: BSD-2-Clause
- Stars: 125
- Forks: 5
- Topics: certificates, homelab, tls-certificate, x509
- Archived: no
Getting Started
Download a pre-built binary from the releases page, or build from source:
git clone https://github.com/serpent213/reactor-ca.git
cd reactor-ca
go build -o ca ./cmd/ca
Then run ca init to create configuration files. See the README for configuration, workflows, and security details.
Alternatives
- certbot: Certbot obtains and renews public certificates from ACME authorities, while ReactorCA manages a private CA and issues certificates for internal services.
Considerations
- ReactorCA is designed primarily for a single root CA directly signing certificates. Intermediate CA support is limited to manually creating and importing one.
- It does not provide certificate revocation, PKCS#12 bundle creation, or an automated renewal daemon. Scheduled renewals require an external tool such as cron or systemd timers.
- Deployment commands execute scripts, so review host configuration and commands before running them.
- Encrypted key protection depends on securely managing the password, SSH identity, or age-plugin hardware identity used to decrypt keys.
Source repository
Open the original repository on GitHub.
16 counted GitHub visits
Related repositories
Similar repositories that may be relevant next.

e2a: Open-Source Email API for Applications and AI Agents
September 29, 2026
e2a is an open-source email API designed for applications and AI agents, offering robust transactional email capabilities and real two-way inboxes. It supports both managed hosting and self-hosting with Docker, providing features like human-in-the-loop approval and advanced content screening. Built in Go, e2a aims to bridge email's universal addressability with the structured data world of AI agents.

Router: Optimize AI Model Selection and Costs for Agentic Systems
September 28, 2026
The Weave-OS Router is an intelligent model router for agentic systems, optimizing AI model selection for every request. It acts as a drop-in proxy for major AI providers, routing prompts to the most suitable model in under 50ms. This solution helps users significantly cut costs, often by 40-70%, simply by changing an endpoint.

KSail: The All-in-One Kubernetes SDK for Cluster Management and GitOps
September 27, 2026
KSail is a comprehensive Kubernetes SDK designed to simplify cluster creation, management, and operation across multiple distributions like Kind, K3d, Talos, and VCluster. It integrates essential features such as GitOps, secrets management, an AI assistant, and an MCP server, making cloud-native development accessible with just Docker or a cloud provider.

Memoh: An Open-Source Multi-Agent Platform with Dedicated AI Workspaces
September 26, 2026
Memoh is an innovative open-source multi-agent platform designed to provide each AI agent with its own dedicated cloud computer. This includes a filesystem, desktop, browser, network, and persistent long-term memory, ensuring agents remain online 24/7. Users can integrate their own API keys or host existing AI models, fostering a versatile and always-on environment for AI development and deployment.