🔐 Certbot Plugin for Azure DNS
An Azure DNS plugin for Certbot that issues certificates, including wildcards, via the ACME dns-01 challenge. A maintained drop-in replacement for certbot-dns-azure.
Why this fork exists
The upstream package certbot-dns-azure pins certbot<4.0, so installing it next to a current certbot downgrades certbot and breaks it. This fork removes the pin and keeps everything else unchanged. Nginx Proxy Manager uses it since version 2.16.
Pick your path
- Nginx Proxy Manager 2.16 or later: nothing to install. Choose “Azure” as DNS provider and follow the Nginx Proxy Manager guide.
- Certbot on a server or in a container: see the quick start below.
- Coming from certbot-dns-azure: see Switching from certbot-dns-azure.
Quick start
The quick start in the docs covers installation, creating the identity and requesting your first certificate.
Features
- Service principals (secret or certificate), managed identities, workload identity and the Azure CLI
- Any number of zones across subscriptions
- Azure public cloud, Azure US Government and Azure China
- DNS delegation via CNAME, and write access limited to a single TXT record
What this fork improves
- Works with current certbot. There is no upper version cap, so pip never downgrades your certbot.
- Supports azure-mgmt-dns 8.x and 9.x.
- Different credentials per zone. Zones can have their own identity, so one certificate can span zones in different Entra ID tenants.
- Configurable TTL for the challenge records with
--dns-azure-ttl. - Reliable zone matching and delegation. Zones match on label boundaries, and delegated record names always keep their full name.
- Safe parallel runs. Creating the challenge record is conditional, so two certbot runs for the same name cannot overwrite each other.
- Config booleans behave.
falsereally switches a method off. - Security and testing. A patched
azure-coreas minimum version, a weekly dependency audit, and a weekly integration test that issues a real certificate against the latest certbot and Azure SDK. - Better documentation. Guides for Nginx Proxy Manager, for switching from the original, and for choosing the authentication method and role scope.
Compatibility
Python 3.10 or newer, certbot 3.0 or newer (no upper bound, so pip never downgrades your certbot), and azure-mgmt-dns 8.x and 9.x.
Documentation and links
The full documentation covers authentication, configuration, DNS delegation, troubleshooting and the changelog.