如何通过AZ CLI将自行创建的SSL证书绑定至Function App?
问题场景与报错
我需要编写脚本自动化完成以下操作:创建Function App、在已有域名下生成子域名、配置SSL加密。但执行SSL证书绑定命令时遇到问题:
执行az functionapp config ssl bind时提示Certificate for thumbprint '{thumbprint_from_previous}' not found,用az functionapp config ssl list -g {resource-group}只能看到其他应用的证书,看不到刚创建的新证书,但在Azure门户中能看到该证书并手动绑定成功。
已执行的关键命令如下:
# 创建Function App az functionapp create -g {resource-group} --consumption-plan-location eastus --runtime python --runtime-version 3.11 --functions-version 4 --name {function_name} --os-type linux --storage-account {storage} # 第一次添加主机名(获取验证所需的secret值) az functionapp config hostname add --hostname {subdomain}.{existing_domain} --name {function_name} -g {resource-group} # 配置DNS验证记录 az network dns record-set txt add-record -g {domain_resource_group} -z {existing_domain} -n asuid.{subdomain} --value {secret_from_previous_step} az network dns record-set cname create -g {domain_resource_group} -z {existing_domain} -n {subdomain} az network dns record-set cname set-record -g {domain_resource_group} -z {existing_domain} --record-set-name {subdomain} --cname {function_name}.azurewebsites.net # 验证主机名配置(第二次执行无报错) az functionapp config ssl create --hostname aopvdesign.usspapps.com -g {resource-group} --name app-aopvdesign # 尝试绑定证书(报错命令) az functionapp config ssl bind --certificate-thumbprint {thumbprint_from_previous} --name {function_name} -g {resource-group} --ssl-type SNI
问题原因与解决方案
1. 证书创建时关联的Function App错误
你执行az functionapp config ssl create时指定的--name app-aopvdesign,如果这个不是要绑定的目标Function App(即{function_name}),证书会被关联到app-aopvdesign,而非目标App,导致CLI在目标App的资源组中找不到证书。
修复步骤:
- 先将证书导出到Key Vault(若没有Key Vault,先创建一个):
# 创建Key Vault(启用部署权限) az keyvault create -g {resource-group} -n {key-vault-name} --enabled-for-deployment true # 从原App导出证书到Key Vault az functionapp config ssl export -g {resource-group} --name app-aopvdesign --certificate-thumbprint {thumbprint_from_previous} --key-vault {key-vault-name} --key-vault-certificate-name {custom-cert-name}
- 再将证书导入到目标Function App:
az functionapp config ssl import -g {resource-group} --name {function_name} --key-vault {key-vault-name} --key-vault-certificate-name {custom-cert-name}
- 最后执行绑定命令:
az functionapp config ssl bind --certificate-thumbprint {thumbprint_from_previous} --name {function_name} -g {resource-group} --ssl-type SNI
2. Azure资源同步延迟或CLI缓存问题
证书创建后,Azure管理平面可能需要1-2分钟同步资源,CLI本地缓存也可能未更新。
修复步骤:
- 等待1-2分钟后重新执行
az functionapp config ssl list -g {resource-group},确认证书是否出现 - 若仍未显示,执行
az account clear清除CLI缓存,重新登录后再尝试查询和绑定
3. 使用证书资源ID直接绑定
如果上述方法无效,可跳过thumbprint,直接用证书的资源ID绑定:
- 获取证书资源ID:
az resource list -g {resource-group} --resource-type Microsoft.Web/certificates --query "[?properties.hostName=='{subdomain}.{existing_domain}'].id" -o tsv
- 使用资源ID执行绑定:
az functionapp config ssl bind --certificate-id {certificate-resource-id} --name {function_name} -g {resource-group} --ssl-type SNI
修正后的完整自动化流程(避免证书关联错误)
确保SSL证书直接创建在目标Function App下,修正az functionapp config ssl create的--name参数为目标App名称:
# 创建Function App az functionapp create -g {resource-group} --consumption-plan-location eastus --runtime python --runtime-version 3.11 --functions-version 4 --name {function_name} --os-type linux --storage-account {storage} # 第一次添加主机名获取验证secret az functionapp config hostname add --hostname {subdomain}.{existing_domain} --name {function_name} -g {resource-group} # 配置DNS记录 az network dns record-set txt add-record -g {domain_resource_group} -z {existing_domain} -n asuid.{subdomain} --value {secret_from_previous_step} az network dns record-set cname create -g {domain_resource_group} -z {existing_domain} -n {subdomain} az network dns record-set cname set-record -g {domain_resource_group} -z {existing_domain} --record-set-name {subdomain} --cname {function_name}.azurewebsites.net # 验证主机名 az functionapp config hostname add --hostname {subdomain}.{existing_domain} --name {function_name} -g {resource-group} # 为目标App创建SSL证书(--name指定目标Function App) az functionapp config ssl create --hostname {subdomain}.{existing_domain} -g {resource-group} --name {function_name} # 提取证书thumbprint thumbprint=$(az functionapp config ssl list -g {resource-group} --query "[?properties.hostName=='{subdomain}.{existing_domain}'].thumbprint" -o tsv) # 绑定证书 az functionapp config ssl bind --certificate-thumbprint $thumbprint --name {function_name} -g {resource-group} --ssl-type SNI
内容的提问来源于stack exchange,提问作者Dean MacGregor
相关产品推荐
相关产品推荐

