You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS新手求助:如何为Elastic Beanstalk后端在ACM申请SSL证书?

How to Request an ACM Certificate for Your Elastic Beanstalk Backend

Hey there! Let's walk through how to get an ACM (AWS Certificate Manager) certificate set up for your Elastic Beanstalk (EB) backend—this will fix those insecure request blocks from your Angular frontend. Here's a clear, step-by-step guide tailored to your setup:

1. First: Assign a Custom Domain to Your EB Backend

Your EB environment has a default domain like your-environment.elasticbeanstalk.com, but you can't use an ACM public certificate for that. Instead, create a subdomain for your backend (e.g., api.yourdomain.com) using your existing GoDaddy domain:

  • Go to your GoDaddy domain management dashboard
  • Add a new DNS record:
    • Type: CNAME (easier if your EB environment uses a load balancer)
    • Host: api (or whatever subdomain you prefer)
    • Point to: Your EB environment's default domain (e.g., your-environment.elasticbeanstalk.com)

2. Request an ACM Public Certificate

Head to the AWS Console and navigate to Certificate Manager:

  • Click Request a certificate > select Request a public certificate > click Next
  • Under Fully qualified domain name, enter your backend's custom subdomain (e.g., api.yourdomain.com). If you might need certificates for other subdomains later, you can add a wildcard like *.yourdomain.com, but a single domain works perfectly for now.
  • Choose DNS validation (it’s automated, plays nicely with GoDaddy, and enables auto-renewal of your certificate) > click Next.
  • Add optional tags if you want, then click Review and request.
  • On the confirmation page, click Confirm and request.

3. Validate the Certificate via DNS

ACM will generate a CNAME record you need to add to your GoDaddy domain:

  • Copy the Name and Value of the CNAME record provided by ACM
  • Go back to your GoDaddy DNS settings, add a new CNAME record with those exact values
  • Save the record, then wait for DNS propagation (this can take a few minutes to an hour—ACM will automatically detect when validation is complete, and your certificate will show as "Issued")

4. Attach the ACM Certificate to Your EB Environment

Now configure your EB environment to use the HTTPS certificate:

  • Go to the Elastic Beanstalk Console, select your backend environment
  • Click Configuration > find the Load balancer section (most EB environments use an Application Load Balancer by default) > click Edit
  • Scroll to the Listeners section:
    • Click Add listener
    • For Protocol, select HTTPS, Port 443
    • Under SSL certificate, choose the ACM certificate you just issued (it will appear in the dropdown)
    • Set the Process to forward to your backend (usually the default default process)
    • Optional: Update the existing HTTP (port 80) listener to redirect to HTTPS, so any HTTP requests get automatically upgraded
  • Click Apply and wait for EB to update your environment (this takes a few minutes)

5. Final Checks & Update Your Frontend

  • Verify your backend is accessible via HTTPS: Visit https://api.yourdomain.com in your browser—you should see a padlock icon indicating a secure connection
  • Update your Angular frontend's API base URL to use the HTTPS version of your backend domain (replace http://your-environment.elasticbeanstalk.com with https://api.yourdomain.com)
  • Deploy the updated frontend, and your requests should no longer be blocked by the browser's insecure content policy

Quick Notes

  • Make sure your EB environment's security group allows inbound traffic on port 443 (HTTPS)
  • If your EB environment uses a single instance (no load balancer), the setup is different—you’d need to install the certificate on the instance itself, but using a load balancer is strongly recommended for easier certificate management and scalability
  • ACM public certificates are free, and they auto-renew as long as DNS validation remains in place

内容的提问来源于stack exchange,提问作者Daniil Andreyevich Baunov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:22:32