You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform为App Service和App Gateway获取Let's Encrypt证书遇错求助

问题:Terraform ACME证书生成失败(Azure DNS挑战)

问题场景

执行以下命令时遇到错误:

terraform plan -out main.tfplan && terraform apply main.tfplan

使用的main.tf内容:

terraform {
  required_providers {
    acme = {
      source  = "vancluever/acme"
      version = "~> 2.0"
    }
  }
}

provider "acme" {
  server_url = "https://acme-staging-v02.api.letsencrypt.org/directory"
}

resource "tls_private_key" "private_key" {
  algorithm = "RSA"
}

resource "acme_registration" "reg" {
  account_key_pem = tls_private_key.private_key.private_key_pem
  email_address   = "myemail@x.com"
}

# As the certificate will be generated in PFX a password is required
resource "random_password" "cert" {
  length  = 24
  special = true
}

resource "acme_certificate" "certificate" {
  account_key_pem           = acme_registration.reg.account_key_pem
  common_name               = "web-app-hosting.com"
  certificate_p12_password  = random_password.cert.result

  dns_challenge {
    provider = "azure"
    config = {
      AZURE_CLIENT_ID       = "XXXXXXXXXXXXX"
      AZURE_CLIENT_SECRET   = "XXXXXXXXXXXXX"
      AZURE_SUBSCRIPTION_ID = "XXXXXXXXXXXXX"
      AZURE_TENANT_ID       = "XXXXXXXXXXXXX"
      AZURE_RESOURCE_GROUP  = "myresource"
    }
  }
}

错误输出

Saved the plan to: main.tfplan

To perform exactly these actions, run the following command to apply:
    terraform apply "main.tfplan"
acme_certificate.certificate: Creating...
╷
│ Error: error creating certificate: error: one or more domains had a problem:
│ [web-app-hosting.com] [web-app-hosting.com] acme: error presenting token: 2 errors occurred:
│       * rpc error: code = Unknown desc = azure: could not find zone for FQDN "_acme-challenge.web-app-hosting.com.": could not find the start of authority for _acme-challenge.web-app-hosting.com.: dial udp: lookup google-public-dns-b.google.com: no such host
│       * error encountered while presenting token for DNS challenge: rpc error: code = Unknown desc = azure: could not find zone for FQDN "_acme-challenge.web-app-hosting.com.": could not find the start of authority for _acme-challenge.web-app-hosting.com.: dial udp: lookup google-public-dns-b.google.com: no such host
│
│   with acme_certificate.certificate,
│   on main.tf line 29, in resource "acme_certificate" "certificate":
│   29: resource "acme_certificate" "certificate" {

错误分析

错误包含两个核心问题:

  1. DNS解析失败:运行Terraform的环境无法访问公共DNS服务器(google-public-dns-b.google.com),导致无法查找域名的DNS权威区域。
  2. Azure DNS区域匹配失败:即使DNS正常,当前配置未明确指定Azure DNS区域,自动查找逻辑无法定位web-app-hosting.com对应的DNS区域。

解决方案

1. 明确指定Azure DNS区域信息

在dns_challenge的config块中添加以下参数,避免自动查找失败:

  • AZURE_DNS_ZONE_NAME:指定域名对应的DNS区域名称(如web-app-hosting.com)
  • 若DNS区域不在AZURE_RESOURCE_GROUP指定的资源组中,额外添加AZURE_DNS_ZONE_RESOURCE_GROUP

修改后的dns_challenge配置示例:

dns_challenge {
  provider = "azure"
  config = {
    AZURE_CLIENT_ID       = "XXXXXXXXXXXXX"
    AZURE_CLIENT_SECRET   = "XXXXXXXXXXXXX"
    AZURE_SUBSCRIPTION_ID = "XXXXXXXXXXXXX"
    AZURE_TENANT_ID       = "XXXXXXXXXXXXX"
    AZURE_RESOURCE_GROUP  = "myresource"
    # 新增:明确指定DNS区域名称
    AZURE_DNS_ZONE_NAME   = "web-app-hosting.com"
    # 若区域在其他资源组,添加此行
    # AZURE_DNS_ZONE_RESOURCE_GROUP = "dns-resource-group"
  }
}

2. 修复运行环境的DNS解析问题

  • 检查运行Terraform的机器/容器是否有出站网络权限,能访问公共DNS服务器。
  • 若在私有网络环境中,配置允许访问公共DNS,或改用Azure DNS服务(如168.63.129.16)作为DNS服务器。

3. 验证Azure服务主体权限

确保配置的AZURE_CLIENT_ID对应的服务主体拥有目标DNS区域的Contributor或DNS Zone Contributor权限,允许添加/删除TXT记录。

4. 可选:直接指定DNS区域ID

如果自动查找仍有问题,可直接指定DNS区域的资源ID:

dns_challenge {
  provider = "azure"
  config = {
    # ... 其他配置 ...
    AZURE_DNS_ZONE_ID = "/subscriptions/XXXXXXXXXXXXX/resourceGroups/myresource/providers/Microsoft.Network/dnszones/web-app-hosting.com"
  }
}

内容的提问来源于stack exchange,提问作者Fabio

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 03:27:54