如何使用Bicep在Azure Key Vault中生成证书?
使用Bicep在Azure Key Vault中创建独立证书
你需要使用Microsoft.KeyVault/vaults/certificates资源类型来在Key Vault中生成证书,而不是Microsoft.Web/certificates(后者是用于App Service的托管证书,必须绑定服务,不符合你的需求)。
完整Bicep示例
下面的代码会在已存在的Key Vault中创建一张自签名证书:
// 定义参数 param keyVaultName string param certificateName string = 'mySelfSignedCert' param certSubject string = 'CN=example.com' param certValidityMonths int = 12 // 引用已有的Key Vault resource keyVault 'Microsoft.KeyVault/vaults@2023-07-01' existing = { name: keyVaultName } // 在Key Vault中创建证书 resource kvCertificate 'Microsoft.KeyVault/vaults/certificates@2023-07-01' = { parent: keyVault name: certificateName properties: { certificatePolicy: { // 配置自签名 issuer issuerParameters: { name: 'Self' } // 密钥相关配置 keyProperties: { exportable: true keySize: 2048 keyType: 'RSA' reuseKey: true } // 密钥保管库中存储证书的格式 secretProperties: { contentType: 'application/x-pkcs12' } // X.509证书属性 x509CertificateProperties: { subject: certSubject validityInMonths: certValidityMonths keyUsage: [ 'digitalSignature' 'keyEncipherment' ] } } } }
关键配置说明
- 资源关联:通过
parent属性将证书资源绑定到目标Key Vault,确保证书创建在指定的密钥保管库内。 - Issuer配置:
issuerParameters.name设为Self表示生成自签名证书;如果需要使用第三方CA(如DigiCert),需先在Key Vault中配置对应的CA集成,再替换此处的 issuer 名称。 - 密钥属性:
exportable: true允许后续导出证书私钥,可根据实际需求调整。
部署命令
使用Azure CLI部署该Bicep文件:
az deployment group create --resource-group <你的资源组名> --template-file <bicep文件路径> --parameters keyVaultName=<你的Key Vault名称>
内容的提问来源于stack exchange,提问作者Marko
相关产品推荐
相关产品推荐

