You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Terraform模块中正确获取Key Vault证书值以创建Azure VPN网关

解决方案:Azure VPN网关证书数据无效问题

核心原因

你错误使用了azurerm_key_vault_certificate_data的key属性作为VPN网关的根证书数据,该属性返回的是密钥的加密内容,而非Azure要求的Base64编码公钥证书,导致网关验证失败。

修复步骤

直接从你创建的azurerm_key_vault_certificate资源中获取正确的证书数据,无需额外的数据源:

修改VPN网关配置代码

将vpn_client_configuration中的public_cert_data替换为证书资源的certificate_data属性:

resource "azurerm_virtual_network_gateway" "vpn-gw" {
  name                = "vng-ab-hub-dev-we"
  location            = azurerm_resource_group.rg[0].location
  resource_group_name = azurerm_resource_group.rg[0].name
  type                = "Vpn"
  vpn_type            = "RouteBased"
  active_active       = true
  enable_bgp          = false
  sku                 = "VpnGw1AZ"

  ip_configuration {
    name                          = "vnet"
    public_ip_address_id          = azurerm_public_ip.vpn-gateway-ip.id
    private_ip_address_allocation = "Static"
    subnet_id                     = azurerm_subnet.gw_snet[0].id
  }

  vpn_client_configuration {
    address_space = ["10.xxx.xx.xx/24"]
    root_certificate {
      name             = "ab-generated-cert"
      # 使用证书资源自带的certificate_data属性,符合Azure要求的格式
      public_cert_data = azurerm_key_vault_certificate.kvc.certificate_data
    }
  }
}

关键说明

  • azurerm_key_vault_certificate的certificate_data属性返回的是Base64编码的PEM格式公钥证书,完全匹配Azure VPN网关对根证书数据的要求。
  • 你之前使用的azurerm_key_vault_certificate_data数据源主要用于获取密钥的原始内容,不适用于VPN网关的证书配置场景。

额外优化建议

确保你的证书配置包含客户端认证用途(VPN客户端连接需要),可在x509_certificate_properties的extended_key_usage中添加客户端认证OID:

x509_certificate_properties {
  extended_key_usage = ["1.3.6.1.5.5.7.3.1", "1.3.6.1.5.5.7.3.2"] # 添加客户端认证
  # 其他属性保持不变
}

内容的提问来源于stack exchange,提问作者asp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.26 09:24:20