You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform ACME证书NXDOMAIN报错:如何获取_acme-challenge的TXT值?

解决Terraform ACME DNS挑战NXDOMAIN问题及获取_acme-challenge TXT记录值

核心问题说明

你碰到的DNS problem: NXDOMAIN looking up TXT for _acme-challenge错误,是因为Let's Encrypt找不到证书验证必需的TXT记录值。这个值不是固定内容,是ACME协议在证书申请流程里动态生成的,手动创建空的TXT记录条目没用,得填入对应生成值。

获取_acme-challenge TXT记录值的具体方法

方法1:从Terraform执行日志提取

执行terraform apply或terraform plan时,ACME provider会在日志里输出需要的TXT记录值:

  • 带调试参数执行命令,查看详细日志:
    terraform apply -debug
    
  • 在日志里搜索包含_acme-challenge的行,会看到类似内容:

    Adding DNS record: _acme-challenge.devtest-oci.example.io. 300 IN TXT "abc123xyz..."
    引号里的abc123xyz...就是要填入的TXT记录值。

方法2:用ACME客户端手动触发验证获取

如果Terraform日志不易抓取,可通过certbot手动发起验证流程获取值:

  1. 安装certbot(以Ubuntu为例):
    sudo apt install certbot
    
  2. 执行手动验证命令,指定你的域名列表:
    certbot certonly --manual --preferred-challenges dns -d devtest-oci.example.io -d *.devtest-oci.example.io -d *.apps.devtest-oci.example.io -d *.sys.devtest-oci.example.io -d test.devtest-oci.example.io
    
  3. 执行过程中,certbot会直接显示需要的TXT记录值,比如:

    Please deploy a DNS TXT record under the name _acme-challenge.devtest-oci.example.io with the following value:
    abc123xyz...

针对你的Terraform配置的额外排查点

  1. 托管区记录格式修正:你的hosted_zones变量里,*.apps.和*.sys.末尾带了点号,这可能导致OCI provider解析记录名称异常,建议去掉末尾点号,改成*.apps和*.sys。
  2. DNS传播验证:添加完TXT记录后,用dig命令确认传播完成:
    dig TXT _acme-challenge.devtest-oci.example.io @8.8.8.8
    
    返回结果里包含正确TXT值,说明传播到位。
  3. OCI权限检查:确认你的OCI账号拥有修改托管区记录的权限,虽然同事能成功,但可能你的账号IAM策略权限有差异。

内容的提问来源于stack exchange,提问作者intu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 07:36:19