多域通配符SSL映射Azure App Service应用的方案选型咨询
First, let's recap your core requirements: fix Safari's strict cross-domain cookie restrictions by aligning API and client domains, while optimizing SSL costs and management for 4 Azure App Services (each with production/staging environments). Let's walk through your existing options, address your questions, and propose a fifth solution you might not have considered.
Analysis of Your Current Options
Option 1: 8 Individual Standard SSL Certificates
This is indeed redundant and cost-prohibitive. Managing 8 separate certificates (each requiring renewal, binding, and monitoring) creates unnecessary overhead—definitely not a scalable or efficient approach for a production environment.
Option 2: Secondary Domain + Wildcard SSL
Your preference here makes sense, and let's clear up your lingering questions:
- Single wildcard SSL on multiple Azure instances: Yes, Azure App Service allows you to bind a single wildcard certificate (e.g.,
*.newdomain.com) to multiple App Service instances, as long as their custom domains match the wildcard pattern (e.g.,api.newdomain.com,a.newdomain.com). Store the certificate in Azure Key Vault and reference it across all applicable instances for centralized, low-fuss management. - Multi-domain wildcard SSL for staging hierarchy: Absolutely. A SAN (Subject Alternative Name) wildcard certificate can include multiple wildcard entries, like
*.prod.newdomain.comand*.staging.newdomain.com. This lets you segregate production and staging environments into distinct subdomain layers, fully meeting your hierarchy needs.
If you're open to migrating your root domain's DNS (not necessarily the WordPress hosting) to Azure, you could even use Azure App Service Managed Certificates (free for wildcard domains) instead of purchasing third-party certificates—more on that in the fifth option.
Option 3: Migrate to Kubernetes + 2 Wildcard Certificates
While technically feasible, this adds significant operational complexity. You'd need to manage a Kubernetes cluster, configure an ingress controller (like NGINX) for SSL termination, and handle ongoing cluster scaling/maintenance. Unless you have plans to adopt microservices or need extreme scaling flexibility, this is overkill compared to sticking with App Service.
Option 4: Unofficial Let's Encrypt Extension for Azure
Free sounds great, but for commercial use, the tradeoffs are too risky:
- Certificates expire every 90 days, and auto-renewal relies on the non-official extension's stability—any downtime here could break your services.
- You won't get official Azure support if something goes wrong with the extension or certificate renewal.
- Managing the extension across 8 environments (4 services × 2 stages) adds more overhead than centralized certificate management.
Fifth Option: Azure Managed Certificates + Partial DNS Migration
If you're willing to migrate your root domain's DNS hosting (not the WordPress site itself) to Azure DNS, this is the most cost-effective and low-maintenance solution:
- Free Wildcard Certificates: Azure offers free managed wildcard certificates for domains hosted in Azure DNS. You can get two certificates:
- One for production:
*.domain.com(coversapi.domain.com,a.domain.com,b.domain.com,c.domain.com) - One for staging:
*.staging.domain.com(coversapi.staging.domain.com,a.staging.domain.com, etc.)
- One for production:
- Auto-Renewal & Management: Azure automatically handles certificate renewal and binding, so you don't have to manually track expiration dates or re-upload certificates.
- No WordPress Migration Needed: You can keep your WordPress site hosted on GoDaddy—only the DNS records need to live in Azure to qualify for managed certificates.
If migrating DNS isn't an option, a close alternative is to purchase a single multi-domain wildcard SAN certificate (covering *.domain.com and *.staging.domain.com), upload it to Azure Key Vault, and bind it to all your App Service instances. This reduces your certificate count from 8 to 1, cutting costs and simplifying management.
Final Recommendation
For your scenario, the best paths are:
- Optimized Option 2: Use a multi-domain wildcard SAN certificate to cover all production and staging subdomains, managed via Azure Key Vault.
- Fifth Option: Migrate DNS to Azure to leverage free managed wildcard certificates, eliminating SSL costs entirely while keeping your WordPress hosting intact.
内容的提问来源于stack exchange,提问作者casaout

