You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何基于Let's Encrypt为Azure多域名应用搭建动态SSL证书生成器

Dynamic SSL Certificate Generation for Multi-Domain Azure Web Apps with OpenResty

Got it, since you already know your way around Certbot for single-domain Nginx setups, let's build on that to set up dynamic SSL for your multi-domain Azure Web App using OpenResty. The key here is using lua-resty-auto-ssl—an OpenResty Lua module that automates Let's Encrypt certificate issuance, renewal, and management on the fly, perfect for your dynamic domain needs.

Step 1: Install OpenResty and Required Dependencies

First, get OpenResty set up on your Azure server (I’ll assume Ubuntu/Debian since it’s common, but adjust commands for your distro):

  • Add the OpenResty repository:
    wget -O - https://openresty.org/package/pubkey.gpg | sudo apt-key add -
    echo "deb http://openresty.org/package/ubuntu $(lsb_release -sc) main" | sudo tee /etc/apt/sources.list.d/openresty.list
    
  • Update packages and install core tools:
    sudo apt update && sudo apt install openresty lua-resty-auto-ssl openssl
    
  • Create a certificate storage directory and set proper permissions (OpenResty runs as www-data by default):
    sudo mkdir -p /etc/resty-auto-ssl
    sudo chown www-data:www-data /etc/resty-auto-ssl
    

Step 2: Configure OpenResty for Dynamic SSL

Open your main OpenResty config file (usually /usr/local/openresty/nginx/conf/nginx.conf or /etc/openresty/nginx.conf) and modify the http block with these settings:

Core Auto-SSL Setup

Add this inside the http block to initialize the auto-ssl module:

# Shared memory for auto-ssl operations
lua_shared_dict auto_ssl 1m;
lua_shared_dict auto_ssl_settings 64k;

init_by_lua_block {
    auto_ssl = (require "resty.auto-ssl").new()

    # Optional: Restrict allowed domains (remove this to allow all valid domains)
    auto_ssl:set("allow_domain", function(domain)
        return domain:match("%.your-approved-domain%.com$") -- Example filter
    end)

    # Set certificate storage path
    auto_ssl:set("dir", "/etc/resty-auto-ssl")

    # Use http-01 challenge (works with your single-IP multi-domain setup)
    auto_ssl:set("challenge", "http-01")

    auto_ssl:init()
}

init_worker_by_lua_block {
    auto_ssl:init_worker()
}

Handle Let's Encrypt Validation Requests

Add this location block inside the http block to respond to ACME challenge checks:

location ^~ /.well-known/acme-challenge/ {
    content_by_lua_block {
        auto_ssl:challenge_server()
    }
}

Catch-All SSL Server Block

Create a default server block that dynamically serves SSL for any incoming domain:

server {
    listen 443 ssl;
    server_name _;  # Catch-all for all domains pointing to your IP

    ssl_certificate_by_lua_block {
        auto_ssl:ssl_certificate()
    }

    ssl_certificate /etc/resty-auto-ssl/ssl_certificate.crt;
    ssl_certificate_key /etc/resty-auto-ssl/ssl_certificate.key;

    # Forward traffic to your Azure Web App (update proxy_pass to your app's internal endpoint)
    location / {
        proxy_pass http://your-web-app-internal-ip:port;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

# Redirect all HTTP traffic to HTTPS
server {
    listen 80;
    server_name _;

    location / {
        return 301 https://$host$request_uri;
    }

    # Pass ACME challenge requests to the auto-ssl handler
    location ^~ /.well-known/acme-challenge/ {
        content_by_lua_block {
            auto_ssl:challenge_server()
        }
    }
}

Step 3: Test the Setup

  • Restart OpenResty to apply changes:
    sudo systemctl restart openresty
    
  • Point a new custom domain's A record to your Azure server's public IP (make sure Azure NSG allows inbound 80/443 traffic).
  • Visit https://your-new-domain.com in a browser or run this command to confirm:
    curl -v https://your-new-domain.com
    
    You’ll see a valid Let’s Encrypt certificate—lua-resty-auto-ssl automatically issued it on the first request.

Step 4: Verify Auto-Renewal

The module handles certificate renewal automatically (30 days before expiration). To check the certificate’s validity:

openssl s_client -connect your-new-domain.com:443 | openssl x509 -noout -dates

Azure-Specific Tips

  • If you’re using Azure App Service instead of a VM, deploy OpenResty as a container (since App Service doesn’t support custom Nginx builds natively) or use Azure Container Apps with OpenResty as your reverse proxy.
  • Ensure all custom domains are verified in Azure per their domain validation steps to ensure proper routing.

内容的提问来源于stack exchange,提问作者Sunny Sharma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 04:04:47