Template
3.1 KiB
3.1 KiB
火山 TOS/CDN 证书续期 Runbook
适用于腾讯云 SSL 自动续期后,需要下载证书并同步到火山引擎证书中心,再绑定到火山 CDN 加速域名的场景。
安全边界
- 下载证书、上传证书、绑定 CDN 证书都是变更操作,执行前必须确认平台、账号、域名、证书 ID、影响、回退和验证方式。
- 不要在命令行参数、聊天、日志或仓库文件里输出私钥。
- 证书下载目录必须放在临时目录,完成后清理。
- 如果错误输出中出现 AK ID、token、私钥或证书私钥内容,后续回复不得复述具体值,并建议轮换对应凭据。
只读发现
确认腾讯云账号:
tccli sts GetCallerIdentity
查询腾讯云证书:
tccli ssl DescribeCertificates --Limit 100 --Offset 0 --SearchKey intelligrow.cn
确认火山账号:
ve sts GetCallerIdentity ---profile intelligrow ---region cn-beijing
查询火山 CDN 域名和当前证书:
ve cdn ListCdnDomains --PageSize 100 ---profile intelligrow ---region cn-beijing
ve cdn DescribeCdnConfig --Domain douyin-video.tos.intelligrow.cn ---profile intelligrow ---region cn-beijing
ve cdn DescribeCdnConfig --Domain video-archive.tos.intelligrow.cn ---profile intelligrow ---region cn-beijing
自动化执行
确认变更后,可用跨平台 Python 脚本执行单个域名的完整流程:
python scripts/update_volcengine_cdn_cert_from_tencent.py \
--domain douyin-video.tos.intelligrow.cn \
--tencent-certificate-id YDC7UTvD \
--volcengine-profile intelligrow \
--volcengine-profile-prefix INTELLIGROW
python scripts/update_volcengine_cdn_cert_from_tencent.py \
--domain video-archive.tos.intelligrow.cn \
--tencent-certificate-id YLB5y62J \
--volcengine-profile intelligrow \
--volcengine-profile-prefix INTELLIGROW
脚本行为:
- 使用
tccli ssl DownloadCertificate下载腾讯云证书。 - 解包后使用 Nginx 证书链和私钥文件。
- 通过
scripts/import_volcengine_certificate.py调用火山证书服务ImportCertificate,避免把私钥放进ve命令行参数。 - 使用
ve cdn BatchDeployCert绑定新证书。 - 查询 CDN 配置和域名下发状态。
- 默认删除临时证书目录;调试时可加
--keep-temp,但调试后必须手动清理。
手工验证
CDN 配置验证:
ve cdn ListCdnDomains --Domain douyin-video.tos.intelligrow.cn --ExactMatch true ---profile intelligrow ---region cn-beijing
ve cdn DescribeCdnConfig --Domain douyin-video.tos.intelligrow.cn ---profile intelligrow ---region cn-beijing
公网 TLS 握手验证:
python -c "import socket, ssl; d='douyin-video.tos.intelligrow.cn'; c=ssl.create_default_context(); s=c.wrap_socket(socket.create_connection((d,443), timeout=10), server_hostname=d); print(s.getpeercert()); s.close()"
回退
如果新证书绑定后异常,且旧证书仍可用:
ve cdn BatchDeployCert --Domain <domain> --CertId <old-volcengine-cert-id> ---profile intelligrow ---region cn-beijing
回退后重复 CDN 配置和公网 TLS 握手验证。