Terraform配置Azure CDN自定义域名HTTPS时遇CertificateType不支持报错求助
Fixing "CertificateType value provided is not supported for this profile for enabling https" in Azure CDN Terraform Configuration
嘿,我马上就发现问题出在哪了——你的CDN Profile用的是Standard_Microsoft SKU,这个SKU根本不支持Dedicated类型的证书,而你在自定义域名的HTTPS配置里偏偏指定了这个值,这就触发了那个报错。
在Azure CDN的规则里,不同SKU支持的证书类型是严格区分的:
Standard_MicrosoftSKU只能使用Azure托管证书,对应的certificate_type必须设为ManagedCertificateDedicated证书类型仅适用于Premium_Verizon或Standard_Verizon这类SKU
你在Azure UI里能顺利操作,是因为UI会自动根据你的CDN SKU匹配正确的证书类型,而Terraform需要你手动明确配置符合要求的值。
修正后的代码
把azurerm_cdn_endpoint_custom_domain资源里的certificate_type改成ManagedCertificate即可:
resource "azurerm_cdn_endpoint_custom_domain" "endpointfrontend" { name = "mykappdev" cdn_endpoint_id = azurerm_cdn_endpoint.cdnendpoint.id host_name = "${azurerm_dns_cname_record.cnamefrontend.name}.${data.azurerm_dns_zone.dnszone.name}" cdn_managed_https { certificate_type = "ManagedCertificate" # 替换为正确的证书类型 protocol_type = "ServerNameIndication" } }
额外说明
如果你确实需要使用Dedicated证书(比如有自定义证书的需求),那你得把CDN Profile的SKU改成支持的类型,比如Standard_Verizon:
resource "azurerm_cdn_profile" "cdnprofile" { name = "mycdn${var.environment}" location = data.azurerm_resource_group.rg.location resource_group_name = data.azurerm_resource_group.rg.name sku = "Standard_Verizon" # 修改为支持Dedicated证书的SKU }
不过要注意,不同SKU的定价和功能差异,需要结合你的实际业务场景来选择。
内容的提问来源于stack exchange,提问作者Leo
相关产品推荐
相关产品推荐

