You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署ACM证书Route53 DNS验证陷入循环求助

解决Terraform中ACM证书DNS验证卡住且Route53无验证记录的问题

问题根源分析

你的配置存在三个关键问题,直接导致验证记录无法生成、验证流程卡住:

  • 冗余且错误的Route53 Data源:公网托管区不需要指定vpc_id,且你已经通过resource创建了托管区,额外的data块会导致依赖解析异常,干扰验证记录的创建逻辑。
  • Route53记录的Zone ID引用错误:错误地使用了data源的zone_id,应该直接引用resource创建的托管区ID。
  • ALB Listener配置矛盾:HTTP协议(80端口)不需要配置ssl_policy和certificate_arn,属于无效配置,应改为HTTPS协议对应443端口。

修正后的完整配置

# ACM Certificate 
resource "aws_acm_certificate" "ssl" {
  domain_name       = "modules.cclab.cloud-castles.com"
  validation_method = "DNS"

  tags = {
    Environment = "test"
  }

  lifecycle {
    create_before_destroy = true
  }
}

# Route53 Zone - 直接使用该资源属性,无需额外data块
resource "aws_route53_zone" "selected" {
  name = "modules.cclab.cloud-castles.com"
}

# Route53 ACM验证记录 - 简化逻辑,直接引用resource的zone_id
resource "aws_route53_record" "acm_validation" {
  for_each = aws_acm_certificate.ssl.domain_validation_options

  allow_overwrite = true
  name            = each.value.resource_record_name
  records         = [each.value.resource_record_value]
  ttl             = 60
  type            = each.value.resource_record_type
  zone_id         = aws_route53_zone.selected.zone_id
}

# ACM证书验证
resource "aws_acm_certificate_validation" "verify" {
  certificate_arn         = aws_acm_certificate.ssl.arn
  validation_record_fqdns = [for record in aws_route53_record.acm_validation : record.fqdn]
}

# ALB HTTPS监听器 - 修正协议与端口的匹配
resource "aws_lb_listener" "alb-listener" {
  load_balancer_arn = aws_lb.alb.arn
  port              = "443"
  protocol          = "HTTPS"
  ssl_policy        = "ELBSecurityPolicy-2016-08"
  certificate_arn   = aws_acm_certificate_validation.verify.certificate_arn

  default_action {
    type             = "forward"
    target_group_arn = aws_lb_target_group.alb-target.arn
  }
}

验证与修复步骤

  1. 先清理现有无效资源:
    terraform destroy
    
  2. 重新初始化并部署:
    terraform init && terraform apply
    
  3. 实时检查Route53记录是否生成:
    aws route53 list-resource-record-sets --hosted-zone-id Z03171471QBEVDH2KPJ6W | grep -A 3 -B 1 "_acme-challenge"
    
    正常情况下能看到对应TXT记录。
  4. 若仍卡住,检查父域NS配置:
    确保modules.cclab.cloud-castles.com的父域(cloud-castles.com)已将NS记录指向你托管区的域名服务器(从aws route53 get-hosted-zone返回的NameServers列表)。
  5. 查看ACM证书状态:
    aws acm describe-certificate --certificate-arn $(terraform output -raw ssl_certificate_arn)
    
    确认验证状态是否有明确错误提示。

内容的提问来源于stack exchange,提问作者Elazar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 15:25:18