Skip to content

New Resource: azurerm_container_app_environment_managed_certificate#31137

Merged
sreallymatt merged 7 commits intohashicorp:mainfrom
jiaweitao001:container_app_env_managed_cert
Apr 14, 2026
Merged

New Resource: azurerm_container_app_environment_managed_certificate#31137
sreallymatt merged 7 commits intohashicorp:mainfrom
jiaweitao001:container_app_env_managed_cert

Conversation

@jiaweitao001
Copy link
Copy Markdown
Collaborator

Community Note

  • Please vote on this PR by adding a 👍 reaction to the original PR to help the community and maintainers prioritize for review
  • Please do not leave comments along the lines of "+1", "me too" or "any updates", they generate extra noise for PR followers and do not help prioritize for review

Description

This PR add support for the azurerm_container_app_environment_managed_certificate resource. This PR replaces #28366 since it has been inactivate for a while.

PR Checklist

  • I have followed the guidelines in our Contributing Documentation.
  • I have checked to ensure there aren't other open Pull Requests for the same update/change.
  • I have checked if my changes close any open issues. If so please include appropriate closing keywords below.
  • I have updated/added Documentation as required written in a helpful and kind way to assist users that may be unfamiliar with the resource / data source.
  • I have used a meaningful PR title to help maintainers and other users understand this change and help prevent duplicate work.
    For example: “resource_name_here - description of change e.g. adding property new_property_name_here

Changes to existing Resource / Data Source

  • I have added an explanation of what my changes do and why I'd like you to include them (This may be covered by linking to an issue above, but may benefit from additional explanation).
  • I have written new tests for my resource or datasource changes & updated any relevant documentation.
  • I have successfully run tests with my changes locally. If not, please provide details on testing challenges that prevented you running the tests.
  • (For changes that include a state migration only). I have manually tested the migration path between relevant versions of the provider.

Testing

  • My submission includes Test coverage as described in the Contribution Guide and the tests pass. (if this is not possible for any reason, please include details of why you did or could not add test coverage)
--- PASS: TestAccContainerAppEnvironmentManagedCertificate_basic (973.35s)
--- PASS: TestAccContainerAppEnvironmentManagedCertificate_domainControlValidationHTTP (971.67s)
--- PASS: TestAccContainerAppEnvironmentManagedCertificate_update (1021.90s)
--- PASS: TestAccContainerAppEnvironmentManagedCertificate_requiresImport (902.01s)
PASS

Change Log

Below please provide what should go into the changelog (if anything) conforming to the Changelog Format documented here.

  • New Resource: azurerm_container_app_environment_managed_certificate

This is a (please select all that apply):

  • Bug Fix
  • New Feature (ie adding a service, resource, or data source)
  • Enhancement
  • Breaking Change

Related Issue(s)

Fixes #27362

AI Assistance Disclosure

  • AI Assisted - This contribution was made by, or with the assistance of, AI/LLMs

Rollback Plan

If a change needs to be reverted, we will publish an updated version of the provider.

Changes to Security Controls

Are there any changes to security controls (access controls, encryption, logging) in this pull request? If so, explain.

Note

If this PR changes meaningfully during the course of review please update the title and description as required.

Copy link
Copy Markdown
Collaborator

@sreallymatt sreallymatt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @jiaweitao001 - I've left some comments inline

- Use consistent error message format with retrieving/updating
- Add nil check for env.Model before accessing nested fields
- Use pointer.FromEnum for DomainControlValidation
- Add CNAME and TXT domain control validation tests
- Shorten DNS record name to avoid exceeding 64 char limit
- Add custom domain with depends_on to docs example

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@sreallymatt
Copy link
Copy Markdown
Collaborator

Hi @jiaweitao001 - it looks like TestAccContainerAppEnvironmentManagedCertificate_domainControlValidationTXT is having some issues, could you investigate?

TXT domain control validation requires longer polling time due to DNS
propagation and CA signing chain being slower than HTTP/CNAME methods.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The CNAME record was pointing to latest_revision_fqdn instead of the
container app's ingress FQDN. Azure requires the CNAME to map directly
to the app's generated domain name (ingress fqdn) for domain validation
to succeed. This was causing TXT validation to stay in Pending state
indefinitely, resulting in context deadline exceeded.

Also reverts the temporary timeout increase from the previous commit.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@jiaweitao001 jiaweitao001 force-pushed the container_app_env_managed_cert branch from e358342 to 74be517 Compare April 10, 2026 02:31
TXT validation is accepted by the API but does not appear to be
functional on the Azure service side - certificates remain in Pending
state indefinitely. Remove the TXT test case and update documentation
to only advertise CNAME and HTTP as supported validation methods.
The validation code still accepts TXT to match the API definition.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@jiaweitao001
Copy link
Copy Markdown
Collaborator Author

Hi @jiaweitao001 - it looks like TestAccContainerAppEnvironmentManagedCertificate_domainControlValidationTXT is having some issues, could you investigate?

Hi @sreallymatt, I removed the TXT validation test case and updated the documentation to only advertise CNAME and HTTP as supported validation methods. TXT exists as an enum value in the API definition, but the service side does not appear to support it currently.

ForceNew: true,
Default: string(managedenvironments.ManagedCertificateDomainControlValidationHTTP),
ValidateFunc: validation.StringInSlice(
managedenvironments.PossibleValuesForManagedCertificateDomainControlValidation(),
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given TXT does not currently appear to function, we should omit it from this ValidateFunc as well. If/when support is added, we can revisit and add it back to the resource.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sure. Removed.

Per review feedback, remove TXT from the allowed validation values
since it does not currently function on the Azure service side.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Copy link
Copy Markdown
Collaborator

@sreallymatt sreallymatt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @jiaweitao001 - LGTM ✅

@sreallymatt sreallymatt merged commit f894a39 into hashicorp:main Apr 14, 2026
31 checks passed
@github-actions github-actions Bot added this to the v4.69.0 milestone Apr 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants