You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Bicep部署带托管证书和自定义域名的Azure容器应用?

通过Bicep部署带托管证书和自定义域名的Azure容器应用示例求助

有没有可用的示例,展示如何通过Bicep部署带有托管证书(Managed Certificate)和自定义域名的Azure容器应用(Azure Container App)?

以下是我目前编写的Bicep代码(我认为还需添加DNS验证相关资源):

var uiHostName = '${env}.example.com'
resource acaEnv 'Microsoft.App/managedEnvironments@2022-11-01-preview' = {
  name: '${appPrefix}-container-env'
  location: location
  tags: tags
  properties: {
    appLogsConfiguration: {
      destination: 'log-analytics'
      logAnalyticsConfiguration: {
        customerId: logAnalyticsWorkspace.properties.customerId
        sharedKey: logAnalyticsWorkspace.listKeys().primarySharedKey
      }
    }
  }
}
resource acaCert 'Microsoft.App/managedEnvironments/managedCertificates@2022-11-01-preview' = {
  name: '${appPrefix}-cert'
  location: location
  tags: tags
  parent: acaEnv
  properties: {
    domainControlValidation: 'CNAME'
    subjectName: uiHostName
  }
}
resource webUI 'Microsoft.App/containerApps@2022-11-01-preview' = {
  name: '${appPrefix}-web-ui-container'
  location: location
  identity: {
    type: 'UserAssigned'
    userAssignedIdentities: {
      '${uaiACR.id}': {}
    }
  }
  properties: {
    managedEnvironmentId: acaEnv.id
    configuration: {
      registries: [
        {
          server: '${acrName}.azurecr.io'
          identity: uaiACR.id
        }
      ]
      ingress: {
        external: true
        targetPort: 80
        allowInsecure: true
        customDomains: [{
          name: uiHostName
          certificateId: acaCert.id
          bindingType: 'SniEnabled'
        }]
      }
      dapr: {
        enabled: true
        appPort: 80
        appId: 'webui'
        appProtocol: 'http'
        enableApiLogging: true
        logLevel: env == 'dev' ? 'debug' : 'info'
      }
    }
    template: {
      containers: [
        {
          image: '${acrName}.azurecr.io/example/whistlerweb:latest'
          name: 'example'
          resources: {
            cpu: json('.5')
            memory: '1Gi'
          }
          env: [
            {
              name: 'APPLICATIONINSIGHTS_CONNECTION_STRING'
              value: applicationInsights.properties.ConnectionString
            }
          ]
          probes: [
            {
              type: 'liveness'
              initialDelaySeconds: 15
              periodSeconds: 30
              failureThreshold: 3
              timeoutSeconds: 1
              httpGet: {
                port: 80
                path: '/health'
              }
            }
          ]
        }
      ]
      scale: {
        minReplicas: 1
      }
    }
  }
}

部署时遇到如下错误:

Creating managed certificate requires hostname 'dev.example.com' added as a custom hostname to a container app in environment

我在谷歌、必应、GitHub及微软文档中均未找到相关示例,但可以在Azure门户手动添加证书和DNS,所以觉得已经接近实现目标。

编辑补充:
经过周末的深入排查,我发现创建证书与为webUI添加自定义域名之间存在依赖循环:没有在容器应用上添加域名则无法创建证书,但没有证书又无法添加域名,不过Azure门户却可以完成此操作。

内容的提问来源于stack exchange,提问作者David Hayes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 05:07:49