You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure容器实例中为InfluxDB v2配置Let's Encrypt证书

解决Azure容器实例部署InfluxDB v2 + Let's Encrypt TLS的方案

以下是无需自定义InfluxDB镜像的三种可行方案,按复杂度和维护成本排序:

方案1:多容器组部署(InfluxDB + CertBot)

利用Azure容器实例的多容器组特性,将CertBot作为独立容器运行,与InfluxDB共享存储卷存放证书,实现证书的申请与自动续约。

步骤:

  1. 创建Azure文件共享作为存储卷,用于共享证书文件:
    az storage share create --account-name <你的存储账户名> --name influxdb-certs
    
  2. 编写多容器组的YAML配置(aci-influxdb-certbot.yaml):
    apiVersion: 2023-05-01
    location: <你的区域>
    name: influxdb-with-certbot
    properties:
      containers:
      - name: influxdb
        properties:
          image: influxdb:2.7
          ports:
          - port: 8086
          - port: 80
          resources:
            requests:
              cpu: 1.0
              memoryInGB: 2.0
          volumeMounts:
          - name: certs-volume
            mountPath: /etc/ssl/certs/influxdb
          command: ["influxd"]
          args:
          - "--tls-cert=/etc/ssl/certs/influxdb/fullchain.pem"
          - "--tls-key=/etc/ssl/certs/influxdb/privkey.pem"
          - "--http-bind-address=:8086"
      - name: certbot
        properties:
          image: certbot/certbot
          resources:
            requests:
              cpu: 0.5
              memoryInGB: 1.0
          volumeMounts:
          - name: certs-volume
            mountPath: /etc/letsencrypt
          command: ["certbot"]
          args:
          - "certonly"
          - "--standalone"
          - "-d"
          - "<你的自定义域名>"
          - "--email"
          - "<你的邮箱>"
          - "--agree-tos"
          - "--non-interactive"
          - "--keep-until-expiring"
          - "--preferred-challenges=http-01"
          - "--http-01-port=80"
      volumes:
      - name: certs-volume
        azureFile:
          shareName: influxdb-certs
          storageAccountName: <你的存储账户名>
          storageAccountKey: <你的存储账户密钥>
      ipAddress:
        type: Public
        ports:
        - protocol: TCP
          port: 80
        - protocol: TCP
          port: 8086
        dnsNameLabel: <你的DNS标签>
      osType: Linux
    
  3. 部署容器组:
    az container create --file aci-influxdb-certbot.yaml
    
  4. 设置CertBot自动续约:
    修改CertBot容器的命令为周期性运行,例如将args替换为:
    - "renew"
    - "--standalone"
    - "--http-01-port=80"
    - "--deploy-hook"
    - "pkill -HUP influxd"
    
    (注:pkill -HUP influxd用于让InfluxDB重新加载证书,无需重启容器)

优缺点:

  • ✅ 无需自定义镜像,组件解耦
  • ❌ 需要维护CertBot的续约逻辑,依赖共享存储的权限配置

方案2:Azure Front Door 反向代理(TLS终止在边缘)

将Azure Front Door作为入口,由Front Door处理Let's Encrypt证书的申请、续约及TLS终止,InfluxDB容器内部仅需HTTP通信,完全无需在容器内处理证书。

步骤:

  1. 创建Azure Front Door实例,添加自定义域名并验证所有权
  2. 在Front Door的自定义域名配置中,启用HTTPS并选择Let's Encrypt作为证书类型,自动完成证书申请与续约
  3. 添加路由规则:
    • 前端主机:你的自定义域名
    • 后端池:选择Azure容器实例的InfluxDB服务(目标端口8086)
    • 路由规则配置:将HTTPS请求转发到后端的HTTP端口
  4. 配置InfluxDB容器仅监听HTTP(无需TLS参数),确保容器组的8086端口对外可访问(或仅允许Front Door的IP段访问)

优缺点:

  • ✅ 零容器端证书维护,Azure自动管理证书续约
  • ✅ 额外获得Front Door的CDN、DDoS防护等能力
  • ❌ 增加了额外的Azure服务成本

方案3:Azure Key Vault 挂载证书

通过Azure Key Vault存储Let's Encrypt证书,将证书直接挂载到InfluxDB容器,避免在容器内运行CertBot。

步骤:

  1. 创建Azure Key Vault实例,启用证书管理功能
  2. 使用Azure Functions或本地运行certbot获取Let's Encrypt证书,并导入到Key Vault
    • 若用Azure Functions自动续约,可编写Python/Node.js函数调用CertBot逻辑或使用Azure证书导入API
  3. 配置容器组的系统分配身份,为该身份添加Key Vault的Certificate User权限
  4. 部署InfluxDB容器时,挂载Key Vault中的证书到容器路径:
    apiVersion: 2023-05-01
    location: <你的区域>
    name: influxdb-with-keyvault
    properties:
      containers:
      - name: influxdb
        properties:
          image: influxdb:2.7
          ports:
          - port: 8086
          resources:
            requests:
              cpu: 1.0
              memoryInGB: 2.0
          volumeMounts:
          - name: certs-volume
            mountPath: /etc/ssl/certs/influxdb
          command: ["influxd"]
          args:
          - "--tls-cert=/etc/ssl/certs/influxdb/<证书文件名>.pem"
          - "--tls-key=/etc/ssl/certs/influxdb/<私钥文件名>.pem"
          - "--http-bind-address=:8086"
      volumes:
      - name: certs-volume
        secret:
          secretName: <Key Vault中的证书名称>
          sourceVault:
            id: <Key Vault的资源ID>
      ipAddress:
        type: Public
        ports:
        - protocol: TCP
          port: 8086
        dnsNameLabel: <你的DNS标签>
      osType: Linux
      identity:
        type: SystemAssigned
    

优缺点:

  • ✅ 证书集中管理,容器内无证书处理逻辑
  • ❌ 需要额外配置Key Vault权限和证书导入/续约的自动化流程

内容的提问来源于stack exchange,提问作者Rufus Buschart

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 22:25:39