You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置Azure CDN自定义域名HTTPS时遇CertificateType不支持报错求助

Fixing "CertificateType value provided is not supported for this profile for enabling https" in Azure CDN Terraform Configuration

嘿,我马上就发现问题出在哪了——你的CDN Profile用的是Standard_Microsoft SKU,这个SKU根本不支持Dedicated类型的证书,而你在自定义域名的HTTPS配置里偏偏指定了这个值,这就触发了那个报错。

在Azure CDN的规则里,不同SKU支持的证书类型是严格区分的:

  • Standard_Microsoft SKU只能使用Azure托管证书,对应的certificate_type必须设为ManagedCertificate
  • Dedicated证书类型仅适用于Premium_Verizon或Standard_Verizon这类SKU

你在Azure UI里能顺利操作,是因为UI会自动根据你的CDN SKU匹配正确的证书类型,而Terraform需要你手动明确配置符合要求的值。

修正后的代码

把azurerm_cdn_endpoint_custom_domain资源里的certificate_type改成ManagedCertificate即可:

resource "azurerm_cdn_endpoint_custom_domain" "endpointfrontend" {
  name            = "mykappdev"
  cdn_endpoint_id = azurerm_cdn_endpoint.cdnendpoint.id
  host_name       = "${azurerm_dns_cname_record.cnamefrontend.name}.${data.azurerm_dns_zone.dnszone.name}"
  cdn_managed_https {
    certificate_type = "ManagedCertificate" # 替换为正确的证书类型
    protocol_type    = "ServerNameIndication"
  }
}

额外说明

如果你确实需要使用Dedicated证书(比如有自定义证书的需求),那你得把CDN Profile的SKU改成支持的类型,比如Standard_Verizon:

resource "azurerm_cdn_profile" "cdnprofile" {
  name                = "mycdn${var.environment}"
  location            = data.azurerm_resource_group.rg.location
  resource_group_name = data.azurerm_resource_group.rg.name
  sku                 = "Standard_Verizon" # 修改为支持Dedicated证书的SKU
}

不过要注意,不同SKU的定价和功能差异,需要结合你的实际业务场景来选择。

内容的提问来源于stack exchange,提问作者Leo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 16:23:11