如何基于Let's Encrypt为Azure多域名应用搭建动态SSL证书生成器
Got it, since you already know your way around Certbot for single-domain Nginx setups, let's build on that to set up dynamic SSL for your multi-domain Azure Web App using OpenResty. The key here is using lua-resty-auto-ssl—an OpenResty Lua module that automates Let's Encrypt certificate issuance, renewal, and management on the fly, perfect for your dynamic domain needs.
Step 1: Install OpenResty and Required Dependencies
First, get OpenResty set up on your Azure server (I’ll assume Ubuntu/Debian since it’s common, but adjust commands for your distro):
- Add the OpenResty repository:
wget -O - https://openresty.org/package/pubkey.gpg | sudo apt-key add - echo "deb http://openresty.org/package/ubuntu $(lsb_release -sc) main" | sudo tee /etc/apt/sources.list.d/openresty.list - Update packages and install core tools:
sudo apt update && sudo apt install openresty lua-resty-auto-ssl openssl - Create a certificate storage directory and set proper permissions (OpenResty runs as
www-databy default):sudo mkdir -p /etc/resty-auto-ssl sudo chown www-data:www-data /etc/resty-auto-ssl
Step 2: Configure OpenResty for Dynamic SSL
Open your main OpenResty config file (usually /usr/local/openresty/nginx/conf/nginx.conf or /etc/openresty/nginx.conf) and modify the http block with these settings:
Core Auto-SSL Setup
Add this inside the http block to initialize the auto-ssl module:
# Shared memory for auto-ssl operations lua_shared_dict auto_ssl 1m; lua_shared_dict auto_ssl_settings 64k; init_by_lua_block { auto_ssl = (require "resty.auto-ssl").new() # Optional: Restrict allowed domains (remove this to allow all valid domains) auto_ssl:set("allow_domain", function(domain) return domain:match("%.your-approved-domain%.com$") -- Example filter end) # Set certificate storage path auto_ssl:set("dir", "/etc/resty-auto-ssl") # Use http-01 challenge (works with your single-IP multi-domain setup) auto_ssl:set("challenge", "http-01") auto_ssl:init() } init_worker_by_lua_block { auto_ssl:init_worker() }
Handle Let's Encrypt Validation Requests
Add this location block inside the http block to respond to ACME challenge checks:
location ^~ /.well-known/acme-challenge/ { content_by_lua_block { auto_ssl:challenge_server() } }
Catch-All SSL Server Block
Create a default server block that dynamically serves SSL for any incoming domain:
server { listen 443 ssl; server_name _; # Catch-all for all domains pointing to your IP ssl_certificate_by_lua_block { auto_ssl:ssl_certificate() } ssl_certificate /etc/resty-auto-ssl/ssl_certificate.crt; ssl_certificate_key /etc/resty-auto-ssl/ssl_certificate.key; # Forward traffic to your Azure Web App (update proxy_pass to your app's internal endpoint) location / { proxy_pass http://your-web-app-internal-ip:port; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } # Redirect all HTTP traffic to HTTPS server { listen 80; server_name _; location / { return 301 https://$host$request_uri; } # Pass ACME challenge requests to the auto-ssl handler location ^~ /.well-known/acme-challenge/ { content_by_lua_block { auto_ssl:challenge_server() } } }
Step 3: Test the Setup
- Restart OpenResty to apply changes:
sudo systemctl restart openresty - Point a new custom domain's A record to your Azure server's public IP (make sure Azure NSG allows inbound 80/443 traffic).
- Visit
https://your-new-domain.comin a browser or run this command to confirm:
You’ll see a valid Let’s Encrypt certificate—curl -v https://your-new-domain.comlua-resty-auto-sslautomatically issued it on the first request.
Step 4: Verify Auto-Renewal
The module handles certificate renewal automatically (30 days before expiration). To check the certificate’s validity:
openssl s_client -connect your-new-domain.com:443 | openssl x509 -noout -dates
Azure-Specific Tips
- If you’re using Azure App Service instead of a VM, deploy OpenResty as a container (since App Service doesn’t support custom Nginx builds natively) or use Azure Container Apps with OpenResty as your reverse proxy.
- Ensure all custom domains are verified in Azure per their domain validation steps to ensure proper routing.
内容的提问来源于stack exchange,提问作者Sunny Sharma

