如何在Azure容器实例中为InfluxDB v2配置Let's Encrypt证书
解决Azure容器实例部署InfluxDB v2 + Let's Encrypt TLS的方案
以下是无需自定义InfluxDB镜像的三种可行方案,按复杂度和维护成本排序:
方案1:多容器组部署(InfluxDB + CertBot)
利用Azure容器实例的多容器组特性,将CertBot作为独立容器运行,与InfluxDB共享存储卷存放证书,实现证书的申请与自动续约。
步骤:
- 创建Azure文件共享作为存储卷,用于共享证书文件:
az storage share create --account-name <你的存储账户名> --name influxdb-certs - 编写多容器组的YAML配置(
aci-influxdb-certbot.yaml):apiVersion: 2023-05-01 location: <你的区域> name: influxdb-with-certbot properties: containers: - name: influxdb properties: image: influxdb:2.7 ports: - port: 8086 - port: 80 resources: requests: cpu: 1.0 memoryInGB: 2.0 volumeMounts: - name: certs-volume mountPath: /etc/ssl/certs/influxdb command: ["influxd"] args: - "--tls-cert=/etc/ssl/certs/influxdb/fullchain.pem" - "--tls-key=/etc/ssl/certs/influxdb/privkey.pem" - "--http-bind-address=:8086" - name: certbot properties: image: certbot/certbot resources: requests: cpu: 0.5 memoryInGB: 1.0 volumeMounts: - name: certs-volume mountPath: /etc/letsencrypt command: ["certbot"] args: - "certonly" - "--standalone" - "-d" - "<你的自定义域名>" - "--email" - "<你的邮箱>" - "--agree-tos" - "--non-interactive" - "--keep-until-expiring" - "--preferred-challenges=http-01" - "--http-01-port=80" volumes: - name: certs-volume azureFile: shareName: influxdb-certs storageAccountName: <你的存储账户名> storageAccountKey: <你的存储账户密钥> ipAddress: type: Public ports: - protocol: TCP port: 80 - protocol: TCP port: 8086 dnsNameLabel: <你的DNS标签> osType: Linux - 部署容器组:
az container create --file aci-influxdb-certbot.yaml - 设置CertBot自动续约:
修改CertBot容器的命令为周期性运行,例如将args替换为:
(注:- "renew" - "--standalone" - "--http-01-port=80" - "--deploy-hook" - "pkill -HUP influxd"pkill -HUP influxd用于让InfluxDB重新加载证书,无需重启容器)
优缺点:
- ✅ 无需自定义镜像,组件解耦
- ❌ 需要维护CertBot的续约逻辑,依赖共享存储的权限配置
方案2:Azure Front Door 反向代理(TLS终止在边缘)
将Azure Front Door作为入口,由Front Door处理Let's Encrypt证书的申请、续约及TLS终止,InfluxDB容器内部仅需HTTP通信,完全无需在容器内处理证书。
步骤:
- 创建Azure Front Door实例,添加自定义域名并验证所有权
- 在Front Door的自定义域名配置中,启用HTTPS并选择Let's Encrypt作为证书类型,自动完成证书申请与续约
- 添加路由规则:
- 前端主机:你的自定义域名
- 后端池:选择Azure容器实例的InfluxDB服务(目标端口8086)
- 路由规则配置:将HTTPS请求转发到后端的HTTP端口
- 配置InfluxDB容器仅监听HTTP(无需TLS参数),确保容器组的8086端口对外可访问(或仅允许Front Door的IP段访问)
优缺点:
- ✅ 零容器端证书维护,Azure自动管理证书续约
- ✅ 额外获得Front Door的CDN、DDoS防护等能力
- ❌ 增加了额外的Azure服务成本
方案3:Azure Key Vault 挂载证书
通过Azure Key Vault存储Let's Encrypt证书,将证书直接挂载到InfluxDB容器,避免在容器内运行CertBot。
步骤:
- 创建Azure Key Vault实例,启用证书管理功能
- 使用Azure Functions或本地运行
certbot获取Let's Encrypt证书,并导入到Key Vault- 若用Azure Functions自动续约,可编写Python/Node.js函数调用CertBot逻辑或使用Azure证书导入API
- 配置容器组的系统分配身份,为该身份添加Key Vault的
Certificate User权限 - 部署InfluxDB容器时,挂载Key Vault中的证书到容器路径:
apiVersion: 2023-05-01 location: <你的区域> name: influxdb-with-keyvault properties: containers: - name: influxdb properties: image: influxdb:2.7 ports: - port: 8086 resources: requests: cpu: 1.0 memoryInGB: 2.0 volumeMounts: - name: certs-volume mountPath: /etc/ssl/certs/influxdb command: ["influxd"] args: - "--tls-cert=/etc/ssl/certs/influxdb/<证书文件名>.pem" - "--tls-key=/etc/ssl/certs/influxdb/<私钥文件名>.pem" - "--http-bind-address=:8086" volumes: - name: certs-volume secret: secretName: <Key Vault中的证书名称> sourceVault: id: <Key Vault的资源ID> ipAddress: type: Public ports: - protocol: TCP port: 8086 dnsNameLabel: <你的DNS标签> osType: Linux identity: type: SystemAssigned
优缺点:
- ✅ 证书集中管理,容器内无证书处理逻辑
- ❌ 需要额外配置Key Vault权限和证书导入/续约的自动化流程
内容的提问来源于stack exchange,提问作者Rufus Buschart
相关产品推荐
相关产品推荐

