[1] https://github.com/acmesh-official/acme.sh
[2] https://github.com/acmesh-official/acme.sh/wiki/dnsapi
[3] https://github.com/acmesh-official/acme.sh/wiki/DNS-API-Dev-...
[1] https://github.com/acmesh-official/acme.sh
[2] https://github.com/acmesh-official/acme.sh/wiki/dnsapi
[3] https://github.com/acmesh-official/acme.sh/wiki/DNS-API-Dev-...
Sometimes you write in shell because it's the lowest common denominator.
I get your point, and was pretty shocked to find acme.sh, but after the certbot PPA made a giant mess of my system I gave it a try. On the other hand, why should I balk at running thousands of lines of bash, but be fine with thousands (or many more) lines of C, Python, PERL...? You can write crappy or beautiful code in any language...
If they’re not doing this then I believe they won’t work on older systems even if compiled with old compiler versions.
It has limitations, and quoting takes a hot minute to grok, but those don't come into play for a surprising amount of medium-large projects when used properly.
I use POSIX sh only and get by with maintainability and handling failure modes just fine.
As a specific example, the ACME protocol requires working with json. Doing this in bash is very difficult and error prone, especially if you want to avoid a dependency on something like jq, as this does.
Also it can be highly locked down - run as it's own unprivileged user, with access only to directories served by another webserver for the ACME handshake, storing certs, and a tightly restricted sudoer to restart the webserver on cert cycle.
Also, CLI utility that supports a bunch of APIs: