dromara/domain-admin: a self-hosted domain and SSL certificate monitor
域名SSL证书监测平台、SSL证书申请自动续签。Domain and SSL Cert monitor System.
At a glance
- What is it?
- Domain Admin is a Python and Vue3 platform that watches domain and SSL certificate expiry across many hosts and can request or renew Let's Encrypt certificates. It suits operators who want one dashboard instead of a spreadsheet, but the frontend lives in a separate repository and the install steps are not in the README.
- Who is it for?
- Adopt domain-admin if you run a known set of domains and certificates across a few hosts and want one place to see expiry dates, with alerts going to email, Webhook, WeCom, DingTalk or Feishu. Do not adopt it if you need a SaaS with an SLA, or if you cannot host the database and scheduler yourself, since the project ships as software you run.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 115 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The expiry problem domain-admin was built to remove
The README states the motivation plainly: domains and SSL certificates are bought or issued through different platforms, so when one expires nobody gets a notification in time and the site goes down. That is a coordination failure, not a technical one, and it is why the project exists as a single dashboard rather than as another certificate tool. The intended user is the person who owns a list of domains, not a single application. If you have one domain and one certificate, a calendar reminder does the same job. If you have thirty domains spread across registrars, a CDN, and two cloud providers, a dashboard that polls each one on a schedule is the difference between a warning and an outage. The README also notes the project can serve as a Flask plus Vue.js template for a separated frontend and backend, which tells you something about the codebase shape: a Python API and a standalone web client, not a monolith.
How domain-admin polls domains and certificates
The repository layout shows a Python package named domain_admin with a main entry point, a requirements directory split into production and other files, and a tests directory. The Dockerfile starts the application with gunicorn bound to port 8000, running domain_admin.main:app, so the HTTP layer is a WSGI application served by gunicorn rather than the Flask development server. Configuration is read from environment variables: .env.example lists DB_CONNECT_URL for the database, APP_MODE for production or development, ALLOW_COMMANDS for shell commands the app may run, ENABLED_REGISTER for open registration, and SHODAN_API_KEY. The presence of a scheduler is implied by the monitoring model rather than spelled out in the README: the app has to check certificates periodically to know when they expire. Certificate coverage listed in the README includes single-domain, multi-domain, wildcard, IP and self-signed certificates. Deployment of certificate files is described as single-host, multi-host and dynamic-host. Notifications go out through email, Webhook, WeCom, DingTalk and Feishu. The README does not document the polling interval, the storage schema, or how the scheduler survives a restart, so treat those as things to inspect in the code or the Read the Docs manual before you rely on them.
Installing domain-admin with Docker and pip
The README does not inline install commands. It points to a separate install page at domain-admin.readthedocs.io/zh_CN/latest/manual/install.html and lists six supported methods: BT Panel, Docker, source, 1Panel, k8s and pip. Because the README gives no commands, the only install artifact you can read directly here is the Dockerfile, which shows what the image does: it copies the project to /app, sets the timezone to Asia/Shanghai, installs build dependencies, installs requirements/production.txt, and starts gunicorn. The image is published as mouday/domain-admin on Docker Hub, and the package is published as domain-admin on PyPI. Configuration comes from a .env file. The example below is copied from .env.example in the repository, with the values left as they appear there.
DB_CONNECT_URL=mysql://root:[email protected]:3306/data
APP_MODE=production
ALLOW_COMMANDS=/opt/nginx/sbin/nginx -s reload
ENABLED_REGISTER=true
SHODAN_API_KEY=DB_CONNECT_URL is the database connection string and is the value you must change first. APP_MODE selects production or development behaviour. ALLOW_COMMANDS is a list of commands the application is permitted to run, and the example is an nginx reload, which is what you would set if domain-admin should reload a web server after deploying a renewed certificate. ENABLED_REGISTER controls whether new users can register themselves; set it to false on anything reachable from the internet. After the container starts, gunicorn listens on port 8000, so that is the port to map. The README also mentions a static preview at mouday.github.io/domain-admin-web where the account and password are arbitrary and the data is simulated, which is useful for looking at the interface before you commit to an install, but it cannot modify anything.
Where domain-admin is the wrong tool
The most concrete limitation is architectural: the frontend is not in this repository. The README says the frontend code lives in another repository, gives a base64-encoded URL for it, and says the full frontend source is available by joining a QQ group or following a WeChat account and replying with a keyword. For a project that presents itself as open source under MIT, that is a real friction point. You can run the published Docker image or install the PyPI package and get a working system, but if you want to modify the interface you have to go through a social channel to get the code. The second limitation is operational: this is software you host. The README notes that a demo server was provided by community members and that it has expired, and it recommends self-hosting for security. That means you own the database, the scheduler, the credentials for your notification channels, and the ALLOW_COMMANDS list, which is a shell execution surface. If nobody on your team wants to run a MySQL instance and keep a container patched, a hosted certificate monitoring service is the better fit. Third, the README does not document rollback, backup, or how to migrate the database between versions, so upgrades should be tested against a copy first.
domain-admin compared with a hosted certificate monitor
The alternative most teams consider is a hosted monitoring service that checks certificates from the outside and emails you before expiry. The difference in approach is where the state lives. A hosted service keeps the domain list and the alert history on the vendor's side; you get an account and a dashboard you do not operate. domain-admin keeps everything in your own database, which is why DB_CONNECT_URL is the first thing you configure. That matters when the domain list itself is sensitive, or when you need the monitor to sit inside a private network and reach internal hosts that an external checker cannot see. The trade-off runs the other way too: with a hosted service you do not patch a container, you do not manage a MySQL instance, and you do not think about whether the scheduler is still running. domain-admin also does more than watch. The README lists Let's Encrypt free certificate application and automatic renewal as an auxiliary feature, plus certificate deployment to single, multiple or dynamic hosts. A pure monitoring service stops at the alert. If you already have a renewal pipeline you trust, that extra surface is unnecessary; if you do not, it is the reason to pick this project.
Maintenance, licence and upgrade cost
The repository is not archived, and the last push was on 2026-06-07. Releases are frequent: v1.6.78 on 2026-06-07, v1.6.77 on 2026-05-24 and v1.6.76 on 2026-04-04. That cadence is a maintenance cost as much as a benefit, because a project that tags releases this often expects you to keep up. The README points to a changelog on Read the Docs rather than inlining version notes, so the upgrade path is: read the changelog, back up the database behind DB_CONNECT_URL, then deploy the new image or package. The licence is MIT, which is permissive and places few obligations on how you redistribute or modify the code. This is not legal advice; check the LICENSE file in the repository if the distinction between MIT and a copyleft licence matters to your organisation. One licence-adjacent point worth noting: the frontend being in a separate repository means the MIT grant you see here covers the backend code in this repository, and you should confirm the licence of the frontend separately before you rely on it.
Editorial conclusion
Adopt domain-admin if you run a known set of domains and certificates across a few hosts and want one place to see expiry dates, with alerts going to email, Webhook, WeCom, DingTalk or Feishu. Do not adopt it if you need a SaaS with an SLA, or if you cannot host the database and scheduler yourself, since the project ships as software you run. Before committing, read the install page at domain-admin.readthedocs.io, confirm the Docker image tag and the DB_CONNECT_URL value you will use, and check whether the ALLOW_COMMANDS entry you plan to set is limited to the exact reload command you need.
Frequently asked questions
What is domain-admin?
It is a domain and SSL certificate monitoring platform built with Python and Vue3, released as the domain-admin package on PyPI and as the mouday/domain-admin Docker image. It watches expiry dates for domains, SSL certificates and hosted certificate files, sends alerts, and can apply for and auto-renew Let's Encrypt certificates.
Which notification channels does domain-admin support?
The README lists email, Webhook, WeCom, DingTalk and Feishu. The credentials for those channels are configured inside your own deployment, which is why the README recommends self-hosting.
Which certificate types can domain-admin monitor?
The README lists single-domain certificates, multi-domain certificates, wildcard certificates, IP certificates and self-signed certificates. Certificate deployment is described as single-host, multi-host and dynamic-host.
How do I install domain-admin?
The README does not include install commands and instead links to the install page at domain-admin.readthedocs.io, which lists BT Panel, Docker, source, 1Panel, k8s and pip as supported methods. The Docker image is published as mouday/domain-admin on Docker Hub.
Does domain-admin include the frontend code?
No. The README states the frontend is in a separate repository and gives a base64-encoded URL for it, and says the full frontend source is obtained by joining a QQ group or replying to a WeChat account. The backend code in this repository is what the MIT licence here covers.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/dromara-domain-admin)