You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过AZ CLI将自行创建的SSL证书绑定至Function App?

问题场景与报错

我需要编写脚本自动化完成以下操作:创建Function App、在已有域名下生成子域名、配置SSL加密。但执行SSL证书绑定命令时遇到问题:
执行az functionapp config ssl bind时提示Certificate for thumbprint '{thumbprint_from_previous}' not found,用az functionapp config ssl list -g {resource-group}只能看到其他应用的证书,看不到刚创建的新证书,但在Azure门户中能看到该证书并手动绑定成功。

已执行的关键命令如下:

# 创建Function App
az functionapp create -g {resource-group} --consumption-plan-location eastus --runtime python --runtime-version 3.11 --functions-version 4 --name {function_name} --os-type linux --storage-account {storage}

# 第一次添加主机名(获取验证所需的secret值)
az functionapp config hostname add --hostname {subdomain}.{existing_domain} --name {function_name} -g {resource-group}

# 配置DNS验证记录
az network dns record-set txt add-record -g {domain_resource_group} -z {existing_domain} -n asuid.{subdomain} --value {secret_from_previous_step}
az network dns record-set cname create -g {domain_resource_group} -z {existing_domain} -n {subdomain}
az network dns record-set cname set-record -g {domain_resource_group} -z {existing_domain} --record-set-name {subdomain} --cname {function_name}.azurewebsites.net

# 验证主机名配置(第二次执行无报错)
az functionapp config ssl create --hostname aopvdesign.usspapps.com -g {resource-group} --name app-aopvdesign

# 尝试绑定证书(报错命令)
az functionapp config ssl bind --certificate-thumbprint {thumbprint_from_previous} --name {function_name} -g {resource-group} --ssl-type SNI
问题原因与解决方案

1. 证书创建时关联的Function App错误

你执行az functionapp config ssl create时指定的--name app-aopvdesign,如果这个不是要绑定的目标Function App(即{function_name}),证书会被关联到app-aopvdesign,而非目标App,导致CLI在目标App的资源组中找不到证书。

修复步骤:

  • 先将证书导出到Key Vault(若没有Key Vault,先创建一个):
# 创建Key Vault(启用部署权限)
az keyvault create -g {resource-group} -n {key-vault-name} --enabled-for-deployment true

# 从原App导出证书到Key Vault
az functionapp config ssl export -g {resource-group} --name app-aopvdesign --certificate-thumbprint {thumbprint_from_previous} --key-vault {key-vault-name} --key-vault-certificate-name {custom-cert-name}
  • 再将证书导入到目标Function App:
az functionapp config ssl import -g {resource-group} --name {function_name} --key-vault {key-vault-name} --key-vault-certificate-name {custom-cert-name}
  • 最后执行绑定命令:
az functionapp config ssl bind --certificate-thumbprint {thumbprint_from_previous} --name {function_name} -g {resource-group} --ssl-type SNI

2. Azure资源同步延迟或CLI缓存问题

证书创建后,Azure管理平面可能需要1-2分钟同步资源,CLI本地缓存也可能未更新。

修复步骤:

  • 等待1-2分钟后重新执行az functionapp config ssl list -g {resource-group},确认证书是否出现
  • 若仍未显示,执行az account clear清除CLI缓存,重新登录后再尝试查询和绑定

3. 使用证书资源ID直接绑定

如果上述方法无效,可跳过thumbprint,直接用证书的资源ID绑定:

  • 获取证书资源ID:
az resource list -g {resource-group} --resource-type Microsoft.Web/certificates --query "[?properties.hostName=='{subdomain}.{existing_domain}'].id" -o tsv
  • 使用资源ID执行绑定:
az functionapp config ssl bind --certificate-id {certificate-resource-id} --name {function_name} -g {resource-group} --ssl-type SNI

修正后的完整自动化流程(避免证书关联错误)

确保SSL证书直接创建在目标Function App下,修正az functionapp config ssl create的--name参数为目标App名称:

# 创建Function App
az functionapp create -g {resource-group} --consumption-plan-location eastus --runtime python --runtime-version 3.11 --functions-version 4 --name {function_name} --os-type linux --storage-account {storage}

# 第一次添加主机名获取验证secret
az functionapp config hostname add --hostname {subdomain}.{existing_domain} --name {function_name} -g {resource-group}

# 配置DNS记录
az network dns record-set txt add-record -g {domain_resource_group} -z {existing_domain} -n asuid.{subdomain} --value {secret_from_previous_step}
az network dns record-set cname create -g {domain_resource_group} -z {existing_domain} -n {subdomain}
az network dns record-set cname set-record -g {domain_resource_group} -z {existing_domain} --record-set-name {subdomain} --cname {function_name}.azurewebsites.net

# 验证主机名
az functionapp config hostname add --hostname {subdomain}.{existing_domain} --name {function_name} -g {resource-group}

# 为目标App创建SSL证书(--name指定目标Function App)
az functionapp config ssl create --hostname {subdomain}.{existing_domain} -g {resource-group} --name {function_name}

# 提取证书thumbprint
thumbprint=$(az functionapp config ssl list -g {resource-group} --query "[?properties.hostName=='{subdomain}.{existing_domain}'].thumbprint" -o tsv)

# 绑定证书
az functionapp config ssl bind --certificate-thumbprint $thumbprint --name {function_name} -g {resource-group} --ssl-type SNI

内容的提问来源于stack exchange,提问作者Dean MacGregor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 21:57:52