Tech riderRev. 4 Oct 2026
- 1Runs onAPI, Linux, self-hosted
- 2CostsFree plan
- 3Deployment modelon premises
- 4ACME supportYes
4 lines stated Written from the maker's own pages: github.com

Overview
Boulder is ranked #12 of 25 in public key infrastructure software on Specifiction. It runs on API, Linux, Self-hosted. There is a free plan.
Boulder plans and pricing
All plansOpen source Free MPL-2.0 licensed · production deployment requires separate implementation and security work github.com · 4 Oct 2026
Compared on public key infrastructure software
- Deployment model
- on_premisesgithub.com
- ACME support
- Yesgithub.com
Facts
- Purpose
- Boulder is an ACME-based certificate authority written in Go and is the software that runs Let's Encrypt.github.com · 4 Oct 2026
- Certificate workflow
- ACME lets a certificate authority verify control of an identifier and lets subscribers issue and revoke certificates for identifiers they control.github.com · 4 Oct 2026
- Components
- Boulder includes web front ends, registration and validation authorities, a certificate authority, storage authority, publisher, and CRL updater.github.com · 4 Oct 2026
- Security design
- The component model separates CA functions by security context, with the certificate authority receiving instructions from the registration authority.github.com · 4 Oct 2026
- Interfaces and storage
- Boulder uses gRPC for communication between components and stores ACME accounts, authorizations, challenges, orders, and certificates.github.com · 4 Oct 2026
- Development setup
- The maintainers recommend Docker and Docker Compose for development and experimentation, and the README says this setup is unsuitable for production.github.com · 4 Oct 2026
- Client compatibility
- The README documents running Certbot or another ACME client against a local Boulder instance.github.com · 4 Oct 2026
- Production fit
- Boulder is built for Let's Encrypt and Web PKI baseline requirements, and the maintainers say it is often not a good fit for other organizations' production use.github.com · 4 Oct 2026
- Production security
- The deployment guide says components use mutual TLS issued from a special-purpose CA and describes firewalling components and limiting exposed ports.github.com · 4 Oct 2026
- Production readiness
- The Docker development environment uses publicly available private key material, exposes debug ports, and is described as brittle to component failure.github.com · 4 Oct 2026
- Support
- The maintainers prioritize support and development work that advances Let's Encrypt's mission and warn that timely support may not be available for other deployments.github.com · 4 Oct 2026
- License
- The project is licensed under the Mozilla Public License 2.0.github.com · 4 Oct 2026
Best Boulder alternatives
See all 12 All accessCh 01 EZCA Free trialAndroidAPI from $200/mo7.7 All accessCh 02 KeyTalk CKMS Free trialAndroidiOS from €5/mo7.4 All accessCh 03 SecureW2 Cloud NAC AndroidAPI 7.4 All accessCh 04 step-ca Free planAPILinux Free to start7.3 All accessCh 05 OpenCA PKI Free planLinuxMac Free to start7.2 All accessCh 06 XiPKI Free planAPILinux Free to start7.1
Where it ranks on Specifiction
Is Boulder yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/letsencrypt/boulder· checked 4 Oct 2026
- github.com/letsencrypt/boulder/wiki/Deployment-%26· checked 4 Oct 2026
