使用Terraform为App Service和App Gateway获取Let's Encrypt证书遇错求助
问题:Terraform ACME证书生成失败(Azure DNS挑战)
问题场景
执行以下命令时遇到错误:
terraform plan -out main.tfplan && terraform apply main.tfplan
使用的main.tf内容:
terraform { required_providers { acme = { source = "vancluever/acme" version = "~> 2.0" } } } provider "acme" { server_url = "https://acme-staging-v02.api.letsencrypt.org/directory" } resource "tls_private_key" "private_key" { algorithm = "RSA" } resource "acme_registration" "reg" { account_key_pem = tls_private_key.private_key.private_key_pem email_address = "myemail@x.com" } # As the certificate will be generated in PFX a password is required resource "random_password" "cert" { length = 24 special = true } resource "acme_certificate" "certificate" { account_key_pem = acme_registration.reg.account_key_pem common_name = "web-app-hosting.com" certificate_p12_password = random_password.cert.result dns_challenge { provider = "azure" config = { AZURE_CLIENT_ID = "XXXXXXXXXXXXX" AZURE_CLIENT_SECRET = "XXXXXXXXXXXXX" AZURE_SUBSCRIPTION_ID = "XXXXXXXXXXXXX" AZURE_TENANT_ID = "XXXXXXXXXXXXX" AZURE_RESOURCE_GROUP = "myresource" } } }
错误输出
Saved the plan to: main.tfplan To perform exactly these actions, run the following command to apply: terraform apply "main.tfplan" acme_certificate.certificate: Creating... ╷ │ Error: error creating certificate: error: one or more domains had a problem: │ [web-app-hosting.com] [web-app-hosting.com] acme: error presenting token: 2 errors occurred: │ * rpc error: code = Unknown desc = azure: could not find zone for FQDN "_acme-challenge.web-app-hosting.com.": could not find the start of authority for _acme-challenge.web-app-hosting.com.: dial udp: lookup google-public-dns-b.google.com: no such host │ * error encountered while presenting token for DNS challenge: rpc error: code = Unknown desc = azure: could not find zone for FQDN "_acme-challenge.web-app-hosting.com.": could not find the start of authority for _acme-challenge.web-app-hosting.com.: dial udp: lookup google-public-dns-b.google.com: no such host │ │ with acme_certificate.certificate, │ on main.tf line 29, in resource "acme_certificate" "certificate": │ 29: resource "acme_certificate" "certificate" {
错误分析
错误包含两个核心问题:
- DNS解析失败:运行Terraform的环境无法访问公共DNS服务器(
google-public-dns-b.google.com),导致无法查找域名的DNS权威区域。 - Azure DNS区域匹配失败:即使DNS正常,当前配置未明确指定Azure DNS区域,自动查找逻辑无法定位
web-app-hosting.com对应的DNS区域。
解决方案
1. 明确指定Azure DNS区域信息
在dns_challenge的config块中添加以下参数,避免自动查找失败:
AZURE_DNS_ZONE_NAME:指定域名对应的DNS区域名称(如web-app-hosting.com)- 若DNS区域不在
AZURE_RESOURCE_GROUP指定的资源组中,额外添加AZURE_DNS_ZONE_RESOURCE_GROUP
修改后的dns_challenge配置示例:
dns_challenge { provider = "azure" config = { AZURE_CLIENT_ID = "XXXXXXXXXXXXX" AZURE_CLIENT_SECRET = "XXXXXXXXXXXXX" AZURE_SUBSCRIPTION_ID = "XXXXXXXXXXXXX" AZURE_TENANT_ID = "XXXXXXXXXXXXX" AZURE_RESOURCE_GROUP = "myresource" # 新增:明确指定DNS区域名称 AZURE_DNS_ZONE_NAME = "web-app-hosting.com" # 若区域在其他资源组,添加此行 # AZURE_DNS_ZONE_RESOURCE_GROUP = "dns-resource-group" } }
2. 修复运行环境的DNS解析问题
- 检查运行Terraform的机器/容器是否有出站网络权限,能访问公共DNS服务器。
- 若在私有网络环境中,配置允许访问公共DNS,或改用Azure DNS服务(如
168.63.129.16)作为DNS服务器。
3. 验证Azure服务主体权限
确保配置的AZURE_CLIENT_ID对应的服务主体拥有目标DNS区域的Contributor或DNS Zone Contributor权限,允许添加/删除TXT记录。
4. 可选:直接指定DNS区域ID
如果自动查找仍有问题,可直接指定DNS区域的资源ID:
dns_challenge { provider = "azure" config = { # ... 其他配置 ... AZURE_DNS_ZONE_ID = "/subscriptions/XXXXXXXXXXXXX/resourceGroups/myresource/providers/Microsoft.Network/dnszones/web-app-hosting.com" } }
内容的提问来源于stack exchange,提问作者Fabio
相关产品推荐
相关产品推荐

