🔐 Certbot Plugin for Azure DNS

An Azure DNS plugin for Certbot that issues certificates, including wildcards, via the ACME dns-01 challenge. A maintained drop-in replacement for certbot-dns-azure.

Why this fork exists

The upstream package certbot-dns-azure pins certbot<4.0, so installing it next to a current certbot downgrades certbot and breaks it. This fork removes the pin and keeps everything else unchanged. Nginx Proxy Manager uses it since version 2.16.

Pick your path

Quick start

The quick start in the docs covers installation, creating the identity and requesting your first certificate.

Features

  • Service principals (secret or certificate), managed identities, workload identity and the Azure CLI
  • Any number of zones across subscriptions
  • Azure public cloud, Azure US Government and Azure China
  • DNS delegation via CNAME, and write access limited to a single TXT record

What this fork improves

  • Works with current certbot. There is no upper version cap, so pip never downgrades your certbot.
  • Supports azure-mgmt-dns 8.x and 9.x.
  • Different credentials per zone. Zones can have their own identity, so one certificate can span zones in different Entra ID tenants.
  • Configurable TTL for the challenge records with --dns-azure-ttl.
  • Reliable zone matching and delegation. Zones match on label boundaries, and delegated record names always keep their full name.
  • Safe parallel runs. Creating the challenge record is conditional, so two certbot runs for the same name cannot overwrite each other.
  • Config booleans behave. false really switches a method off.
  • Security and testing. A patched azure-core as minimum version, a weekly dependency audit, and a weekly integration test that issues a real certificate against the latest certbot and Azure SDK.
  • Better documentation. Guides for Nginx Proxy Manager, for switching from the original, and for choosing the authentication method and role scope.

Compatibility

Python 3.10 or newer, certbot 3.0 or newer (no upper bound, so pip never downgrades your certbot), and azure-mgmt-dns 8.x and 9.x.

Documentation and links

The full documentation covers authentication, configuration, DNS delegation, troubleshooting and the changelog.