如何用Bicep部署带托管证书和自定义域名的Azure容器应用?
通过Bicep部署带托管证书和自定义域名的Azure容器应用示例求助
有没有可用的示例,展示如何通过Bicep部署带有托管证书(Managed Certificate)和自定义域名的Azure容器应用(Azure Container App)?
以下是我目前编写的Bicep代码(我认为还需添加DNS验证相关资源):
var uiHostName = '${env}.example.com' resource acaEnv 'Microsoft.App/managedEnvironments@2022-11-01-preview' = { name: '${appPrefix}-container-env' location: location tags: tags properties: { appLogsConfiguration: { destination: 'log-analytics' logAnalyticsConfiguration: { customerId: logAnalyticsWorkspace.properties.customerId sharedKey: logAnalyticsWorkspace.listKeys().primarySharedKey } } } } resource acaCert 'Microsoft.App/managedEnvironments/managedCertificates@2022-11-01-preview' = { name: '${appPrefix}-cert' location: location tags: tags parent: acaEnv properties: { domainControlValidation: 'CNAME' subjectName: uiHostName } } resource webUI 'Microsoft.App/containerApps@2022-11-01-preview' = { name: '${appPrefix}-web-ui-container' location: location identity: { type: 'UserAssigned' userAssignedIdentities: { '${uaiACR.id}': {} } } properties: { managedEnvironmentId: acaEnv.id configuration: { registries: [ { server: '${acrName}.azurecr.io' identity: uaiACR.id } ] ingress: { external: true targetPort: 80 allowInsecure: true customDomains: [{ name: uiHostName certificateId: acaCert.id bindingType: 'SniEnabled' }] } dapr: { enabled: true appPort: 80 appId: 'webui' appProtocol: 'http' enableApiLogging: true logLevel: env == 'dev' ? 'debug' : 'info' } } template: { containers: [ { image: '${acrName}.azurecr.io/example/whistlerweb:latest' name: 'example' resources: { cpu: json('.5') memory: '1Gi' } env: [ { name: 'APPLICATIONINSIGHTS_CONNECTION_STRING' value: applicationInsights.properties.ConnectionString } ] probes: [ { type: 'liveness' initialDelaySeconds: 15 periodSeconds: 30 failureThreshold: 3 timeoutSeconds: 1 httpGet: { port: 80 path: '/health' } } ] } ] scale: { minReplicas: 1 } } } }
部署时遇到如下错误:
Creating managed certificate requires hostname 'dev.example.com' added as a custom hostname to a container app in environment
我在谷歌、必应、GitHub及微软文档中均未找到相关示例,但可以在Azure门户手动添加证书和DNS,所以觉得已经接近实现目标。
编辑补充:
经过周末的深入排查,我发现创建证书与为webUI添加自定义域名之间存在依赖循环:没有在容器应用上添加域名则无法创建证书,但没有证书又无法添加域名,不过Azure门户却可以完成此操作。
内容的提问来源于stack exchange,提问作者David Hayes
相关产品推荐
相关产品推荐

