---
title: Charmhub | Deploy Observability Libs using Charmhub - The Open Operator Collection
description: Deploy the latest version of Observability Libs as a Kubernetes Operator
  on any cloud.
url: https://charmhub.io/observability-libs/libraries/cert_handler
---

# Observability Libs

[Jon Seager](https://charmhub.io/publisher/jnsgruk "View all packages from Jon Seager")

* [Jon Seager](https://charmhub.io/publisher/jnsgruk "View all packages from Jon Seager")

Platform:

edge 454c1f8

```
juju deploy observability-libs --channel edge
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

[Toggle side navigation](https://charmhub.io/observability-libs/libraries/cert_handler#drawer)

## charms.observability\_libs.v1.cert\_handler

* [*Docstrings*Docstrings](https://charmhub.io/observability-libs/libraries/cert_handler)
  [*Code*Source code](https://charmhub.io/observability-libs/libraries/cert_handler/source-code)
* + Download

    Fetch library

    ```
    charmcraft fetch-lib charms.observability_libs.v1.cert_handler
    ```

    [Download cert\_handler.py](https://charmhub.io/observability-libs/libraries/cert_handler/download)
  + *Last updated* 06 Oct 2025
  + *Revision* Library version 1.19

#### [DEPRECATED] CertHandler Library.

The `cert_handler` library is deprecated and will be **removed in October 2025**.
Please migrate to the `tls_certificates_interface.v4` charm library.

---

Index

* [def is\_ip\_address(
  value
  )](https://charmhub.io/observability-libs/libraries/cert_handler#is_ip_address)
* [def split\_chain(
  chain
  )](https://charmhub.io/observability-libs/libraries/cert_handler#split_chain)
* [class CertChanged](https://charmhub.io/observability-libs/libraries/cert_handler#certchanged)
* [class CertHandlerEvents](https://charmhub.io/observability-libs/libraries/cert_handler#certhandlerevents)
* [class Vault](https://charmhub.io/observability-libs/libraries/cert_handler#vault)
* + [def \_\_init\_\_(
    self,
    backend)](https://charmhub.io/observability-libs/libraries/cert_handler#vault-__init__)
* + [def store(
    self,
    contents,
    clear)](https://charmhub.io/observability-libs/libraries/cert_handler#vault-store)
* + [def get\_value(
    self,
    key)](https://charmhub.io/observability-libs/libraries/cert_handler#vault-get_value)
* + [def retrieve(
    self)](https://charmhub.io/observability-libs/libraries/cert_handler#vault-retrieve)
* + [def clear(
    self)](https://charmhub.io/observability-libs/libraries/cert_handler#vault-clear)
* [class CertHandler](https://charmhub.io/observability-libs/libraries/cert_handler#certhandler)
* + [def \_\_init\_\_(
    self,
    charm)](https://charmhub.io/observability-libs/libraries/cert_handler#certhandler-__init__)
* + [def enabled(
    self)](https://charmhub.io/observability-libs/libraries/cert_handler#certhandler-enabled)
* + [def available(
    self)](https://charmhub.io/observability-libs/libraries/cert_handler#certhandler-available)
* + [def relation(
    self)](https://charmhub.io/observability-libs/libraries/cert_handler#certhandler-relation)
* + [def private\_key(
    self)](https://charmhub.io/observability-libs/libraries/cert_handler#certhandler-private_key)
* + [def get\_cert(
    self)](https://charmhub.io/observability-libs/libraries/cert_handler#certhandler-get_cert)
* + [def ca\_cert(
    self)](https://charmhub.io/observability-libs/libraries/cert_handler#certhandler-ca_cert)
* + [def server\_cert(
    self)](https://charmhub.io/observability-libs/libraries/cert_handler#certhandler-server_cert)
* + [def chain(
    self)](https://charmhub.io/observability-libs/libraries/cert_handler#certhandler-chain)

#### def is\_ip\_address(value: str)

Description

Return True if the input value is a valid IPv4 address; False otherwise. None

#### def split\_chain(chain: str)

Split a chain string in to individual cert strings.

Arguments

chain

The chain to split.

Returns

A list of cert strings.

#### class CertChanged

Description

Event raised when a cert is changed (becomes available or revoked). None

#### class CertHandlerEvents

Description

Events for CertHandler. None

#### class Vault

Description

Simple application secret wrapper for local usage. None

Methods

Vault.
\_\_init\_\_(

*self*

,
backend: \_VaultBackend
)

Vault.
store(

*self*

,
contents

,
clear: bool
)

Description

Store these contents in the vault overriding whatever is there. None

Vault.
get\_value(

*self*

,
key: str
)

Description

Like retrieve, but single-value. None

Vault.
retrieve(

*self*
)

Description

Return the full vault content. None

Vault.
clear(

*self*
)

Description

Clear the vault. None

#### class CertHandler

Description

A wrapper for the requirer side of the TLS Certificates charm library. None

Methods

CertHandler.
\_\_init\_\_(

*self*

,
charm: CharmBase
)

CertHandler is used to wrap TLS Certificates management operations for charms.

Arguments

charm

The owning charm.

key

A manually-crafted, static, unique identifier used by ops to identify events.
It shouldn't change between one event to another.

certificates\_relation\_name

Name of the certificates relation over which we obtain TLS certificates.
Must match metadata.yaml.

peer\_relation\_name

Name of a peer relation used to store our secrets.
Only used on older Juju versions where secrets are not supported.
Must match metadata.yaml.

cert\_subject

Custom subject. Name collisions are under the caller's responsibility.

sans

DNS names. If none are given, use FQDN.

refresh\_events

[DEPRECATED].

Description

CerHandler manages one single cert.

CertHandler.
enabled(

*self*
)

Boolean indicating whether the charm has a tls\_certificates relation.

Description

See also the `available` property.

CertHandler.
available(

*self*
)

Description

Return True if all certs are available in relation data; False otherwise. None

CertHandler.
relation(

*self*
)

Description

The "certificates" relation. None

CertHandler.
private\_key(

*self*
)

Private key.

Description

BEWARE: if the vault misbehaves, the backing secret is removed, the peer relation dies
or whatever, we might be calling generate\_private\_key() again and cause a desync
with the CSR because it's going to be signed with an outdated key we have no way of retrieving.
The caller needs to ensure that if the vault backend gets reset, then so does the csr.

TODO: we could consider adding a way to verify if the csr was signed by our privkey,
and do that on collect\_unit\_status as a consistency check

CertHandler.
get\_cert(

*self*
)

Description

Get the certificate from relation data. None

CertHandler.
ca\_cert(

*self*
)

Description

CA Certificate. None

CertHandler.
server\_cert(

*self*
)

Description

Server Certificate. None

CertHandler.
chain(

*self*
)

Return the entire chain bundled as a single PEM string. This includes, if available, the certificate, intermediate CAs, and the root CA.

Description

If the server certificate is not set in the chain by the provider, we'll add it
to the top of the chain so that it could be used by a server.
