LetsEncrypt: Support for DNS alias in Azure#1639
Merged
hnrkndrssn merged 3 commits intoOctopusDeploy:masterfrom Nov 28, 2025
Merged
LetsEncrypt: Support for DNS alias in Azure#1639hnrkndrssn merged 3 commits intoOctopusDeploy:masterfrom
hnrkndrssn merged 3 commits intoOctopusDeploy:masterfrom
Conversation
|
Start Hyponome locally |
hnrkndrssn
approved these changes
Nov 28, 2025
Contributor
hnrkndrssn
left a comment
There was a problem hiding this comment.
Looks good to me 👍 Thanks for your contribution!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Background
Reference https://poshac.me/docs/v4/Guides/Using-DNS-Challenge-Aliases/
The setup:
mydomain.comis highly locked down. Only account type that can be created here is of the admin types (not something I want a service account to use).myotherdomain.comDNS is hosted in Azure, and allows more granular permission control for service accounts._acme-challenge.mydomain.comis an existing CNAME alias forthealias.myotherdomain.comResults
Providing the DNS alias parameter as
thealias.myotherdomain.comto POSH-Acme'sNew-PACertificateresults in the acme challenge nonce getting written to the TXT record ofthealias.myotherdomain.comand the verification of_acme-challenge.mydomain.comsucceeds.Before
--
After
Notice the alias for the
.netdomain is used but the challenge is for the.comone.Pre-requisites
Idshould be a GUID that is not00000000-0000-0000-0000-000000000000Idproperty (updating theIdwill break the Library sync functionality in Octopus).Versionshould be incremented, otherwise the integration with Octopus won't update the step template correctly$LastModifiedByfield must be present, and (optionally) updated with the correct authorCategoryhas been created:{categoryname}.pngmust be present under thestep-templates/logosfolderswitchin thehumanizefunction ingulpfile.babel.jsmust have acasestatement corresponding to it