1. Packages
  2. Packages
  3. Azure Classic
  4. API Docs
  5. cdn
  6. FrontdoorCustomDomain

We recommend using Azure Native.

Viewing docs for Azure v6.38.0
published on Wednesday, May 27, 2026 by Pulumi
azure logo

We recommend using Azure Native.

Viewing docs for Azure v6.38.0
published on Wednesday, May 27, 2026 by Pulumi

    Manages a Front Door (standard/premium) Custom Domain.

    Note: If you are using Terraform to manage your DNS Auth and DNS CNAME records for your Custom Domain you will need to add configuration blocks for both the azure.dns.TxtRecord (see the Example DNS Auth TXT Record Usage below) and the azure.dns.CNameRecord (see the Example CNAME Record Usage below) to your configuration file.

    Example Usage

    import * as pulumi from "@pulumi/pulumi";
    import * as azure from "@pulumi/azure";
    
    const example = new azure.core.ResourceGroup("example", {
        name: "example-resource-group",
        location: "West Europe",
    });
    const exampleZone = new azure.dns.Zone("example", {
        name: "fabrikam.com",
        resourceGroupName: example.name,
    });
    const exampleFrontdoorProfile = new azure.cdn.FrontdoorProfile("example", {
        name: "example-cdn-frontdoor-profile",
        resourceGroupName: example.name,
        skuName: "Standard_AzureFrontDoor",
    });
    const exampleFrontdoorEndpoint = new azure.cdn.FrontdoorEndpoint("example", {
        name: "example-cdn-frontdoor-endpoint",
        cdnFrontdoorProfileId: exampleFrontdoorProfile.id,
    });
    const exampleFrontdoorOriginGroup = new azure.cdn.FrontdoorOriginGroup("example", {
        name: "example-cdn-frontdoor-origin-group",
        cdnFrontdoorProfileId: exampleFrontdoorProfile.id,
        loadBalancing: {},
    });
    const exampleFrontdoorOrigin = new azure.cdn.FrontdoorOrigin("example", {
        name: "example-cdn-frontdoor-origin",
        cdnFrontdoorOriginGroupId: exampleFrontdoorOriginGroup.id,
        hostName: "contoso.fabrikam.com",
        certificateNameCheckEnabled: false,
    });
    const exampleFrontdoorCustomDomain = new azure.cdn.FrontdoorCustomDomain("example", {
        name: "example-cdn-frontdoor-custom-domain",
        cdnFrontdoorProfileId: exampleFrontdoorProfile.id,
        dnsZoneId: exampleZone.id,
        hostName: exampleFrontdoorOrigin.hostName,
        tls: {
            certificateType: "ManagedCertificate",
            minimumVersion: "TLS12",
        },
    });
    const exampleFrontdoorRoute = new azure.cdn.FrontdoorRoute("example", {
        name: "example-cdn-frontdoor-route",
        cdnFrontdoorEndpointId: exampleFrontdoorEndpoint.id,
        cdnFrontdoorOriginGroupId: exampleFrontdoorOriginGroup.id,
        cdnFrontdoorOriginIds: [exampleFrontdoorOrigin.id],
        cdnFrontdoorCustomDomainIds: [exampleFrontdoorCustomDomain.id],
        patternsToMatches: ["/*"],
        supportedProtocols: [
            "Http",
            "Https",
        ],
    });
    const exampleFrontdoorFirewallPolicy = new azure.cdn.FrontdoorFirewallPolicy("example", {
        name: "examplecdnfrontdoorfirewallpolicy",
        resourceGroupName: example.name,
        skuName: exampleFrontdoorProfile.skuName,
        mode: "Prevention",
    });
    const exampleFrontdoorSecurityPolicy = new azure.cdn.FrontdoorSecurityPolicy("example", {
        name: "example-cdn-frontdoor-security-policy",
        cdnFrontdoorProfileId: exampleFrontdoorProfile.id,
        securityPolicies: {
            firewall: {
                cdnFrontdoorFirewallPolicyId: exampleFrontdoorFirewallPolicy.id,
                association: {
                    domains: [{
                        cdnFrontdoorDomainId: exampleFrontdoorCustomDomain.id,
                    }],
                    patternsToMatch: "/*",
                },
            },
        },
    });
    
    import pulumi
    import pulumi_azure as azure
    
    example = azure.core.ResourceGroup("example",
        name="example-resource-group",
        location="West Europe")
    example_zone = azure.dns.Zone("example",
        name="fabrikam.com",
        resource_group_name=example.name)
    example_frontdoor_profile = azure.cdn.FrontdoorProfile("example",
        name="example-cdn-frontdoor-profile",
        resource_group_name=example.name,
        sku_name="Standard_AzureFrontDoor")
    example_frontdoor_endpoint = azure.cdn.FrontdoorEndpoint("example",
        name="example-cdn-frontdoor-endpoint",
        cdn_frontdoor_profile_id=example_frontdoor_profile.id)
    example_frontdoor_origin_group = azure.cdn.FrontdoorOriginGroup("example",
        name="example-cdn-frontdoor-origin-group",
        cdn_frontdoor_profile_id=example_frontdoor_profile.id,
        load_balancing={})
    example_frontdoor_origin = azure.cdn.FrontdoorOrigin("example",
        name="example-cdn-frontdoor-origin",
        cdn_frontdoor_origin_group_id=example_frontdoor_origin_group.id,
        host_name="contoso.fabrikam.com",
        certificate_name_check_enabled=False)
    example_frontdoor_custom_domain = azure.cdn.FrontdoorCustomDomain("example",
        name="example-cdn-frontdoor-custom-domain",
        cdn_frontdoor_profile_id=example_frontdoor_profile.id,
        dns_zone_id=example_zone.id,
        host_name=example_frontdoor_origin.host_name,
        tls={
            "certificate_type": "ManagedCertificate",
            "minimum_version": "TLS12",
        })
    example_frontdoor_route = azure.cdn.FrontdoorRoute("example",
        name="example-cdn-frontdoor-route",
        cdn_frontdoor_endpoint_id=example_frontdoor_endpoint.id,
        cdn_frontdoor_origin_group_id=example_frontdoor_origin_group.id,
        cdn_frontdoor_origin_ids=[example_frontdoor_origin.id],
        cdn_frontdoor_custom_domain_ids=[example_frontdoor_custom_domain.id],
        patterns_to_matches=["/*"],
        supported_protocols=[
            "Http",
            "Https",
        ])
    example_frontdoor_firewall_policy = azure.cdn.FrontdoorFirewallPolicy("example",
        name="examplecdnfrontdoorfirewallpolicy",
        resource_group_name=example.name,
        sku_name=example_frontdoor_profile.sku_name,
        mode="Prevention")
    example_frontdoor_security_policy = azure.cdn.FrontdoorSecurityPolicy("example",
        name="example-cdn-frontdoor-security-policy",
        cdn_frontdoor_profile_id=example_frontdoor_profile.id,
        security_policies={
            "firewall": {
                "cdn_frontdoor_firewall_policy_id": example_frontdoor_firewall_policy.id,
                "association": {
                    "domains": [{
                        "cdn_frontdoor_domain_id": example_frontdoor_custom_domain.id,
                    }],
                    "patterns_to_match": "/*",
                },
            },
        })
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/cdn"
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/core"
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/dns"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		example, err := core.NewResourceGroup(ctx, "example", &core.ResourceGroupArgs{
    			Name:     pulumi.String("example-resource-group"),
    			Location: pulumi.String("West Europe"),
    		})
    		if err != nil {
    			return err
    		}
    		exampleZone, err := dns.NewZone(ctx, "example", &dns.ZoneArgs{
    			Name:              pulumi.String("fabrikam.com"),
    			ResourceGroupName: example.Name,
    		})
    		if err != nil {
    			return err
    		}
    		exampleFrontdoorProfile, err := cdn.NewFrontdoorProfile(ctx, "example", &cdn.FrontdoorProfileArgs{
    			Name:              pulumi.String("example-cdn-frontdoor-profile"),
    			ResourceGroupName: example.Name,
    			SkuName:           pulumi.String("Standard_AzureFrontDoor"),
    		})
    		if err != nil {
    			return err
    		}
    		exampleFrontdoorEndpoint, err := cdn.NewFrontdoorEndpoint(ctx, "example", &cdn.FrontdoorEndpointArgs{
    			Name:                  pulumi.String("example-cdn-frontdoor-endpoint"),
    			CdnFrontdoorProfileId: exampleFrontdoorProfile.ID(),
    		})
    		if err != nil {
    			return err
    		}
    		exampleFrontdoorOriginGroup, err := cdn.NewFrontdoorOriginGroup(ctx, "example", &cdn.FrontdoorOriginGroupArgs{
    			Name:                  pulumi.String("example-cdn-frontdoor-origin-group"),
    			CdnFrontdoorProfileId: exampleFrontdoorProfile.ID(),
    			LoadBalancing:         &cdn.FrontdoorOriginGroupLoadBalancingArgs{},
    		})
    		if err != nil {
    			return err
    		}
    		exampleFrontdoorOrigin, err := cdn.NewFrontdoorOrigin(ctx, "example", &cdn.FrontdoorOriginArgs{
    			Name:                        pulumi.String("example-cdn-frontdoor-origin"),
    			CdnFrontdoorOriginGroupId:   exampleFrontdoorOriginGroup.ID(),
    			HostName:                    pulumi.String("contoso.fabrikam.com"),
    			CertificateNameCheckEnabled: pulumi.Bool(false),
    		})
    		if err != nil {
    			return err
    		}
    		exampleFrontdoorCustomDomain, err := cdn.NewFrontdoorCustomDomain(ctx, "example", &cdn.FrontdoorCustomDomainArgs{
    			Name:                  pulumi.String("example-cdn-frontdoor-custom-domain"),
    			CdnFrontdoorProfileId: exampleFrontdoorProfile.ID(),
    			DnsZoneId:             exampleZone.ID(),
    			HostName:              exampleFrontdoorOrigin.HostName,
    			Tls: &cdn.FrontdoorCustomDomainTlsArgs{
    				CertificateType: pulumi.String("ManagedCertificate"),
    				MinimumVersion:  pulumi.String("TLS12"),
    			},
    		})
    		if err != nil {
    			return err
    		}
    		_, err = cdn.NewFrontdoorRoute(ctx, "example", &cdn.FrontdoorRouteArgs{
    			Name:                      pulumi.String("example-cdn-frontdoor-route"),
    			CdnFrontdoorEndpointId:    exampleFrontdoorEndpoint.ID(),
    			CdnFrontdoorOriginGroupId: exampleFrontdoorOriginGroup.ID(),
    			CdnFrontdoorOriginIds: pulumi.StringArray{
    				exampleFrontdoorOrigin.ID(),
    			},
    			CdnFrontdoorCustomDomainIds: pulumi.StringArray{
    				exampleFrontdoorCustomDomain.ID(),
    			},
    			PatternsToMatches: pulumi.StringArray{
    				pulumi.String("/*"),
    			},
    			SupportedProtocols: pulumi.StringArray{
    				pulumi.String("Http"),
    				pulumi.String("Https"),
    			},
    		})
    		if err != nil {
    			return err
    		}
    		exampleFrontdoorFirewallPolicy, err := cdn.NewFrontdoorFirewallPolicy(ctx, "example", &cdn.FrontdoorFirewallPolicyArgs{
    			Name:              pulumi.String("examplecdnfrontdoorfirewallpolicy"),
    			ResourceGroupName: example.Name,
    			SkuName:           exampleFrontdoorProfile.SkuName,
    			Mode:              pulumi.String("Prevention"),
    		})
    		if err != nil {
    			return err
    		}
    		_, err = cdn.NewFrontdoorSecurityPolicy(ctx, "example", &cdn.FrontdoorSecurityPolicyArgs{
    			Name:                  pulumi.String("example-cdn-frontdoor-security-policy"),
    			CdnFrontdoorProfileId: exampleFrontdoorProfile.ID(),
    			SecurityPolicies: &cdn.FrontdoorSecurityPolicySecurityPoliciesArgs{
    				Firewall: &cdn.FrontdoorSecurityPolicySecurityPoliciesFirewallArgs{
    					CdnFrontdoorFirewallPolicyId: exampleFrontdoorFirewallPolicy.ID(),
    					Association: &cdn.FrontdoorSecurityPolicySecurityPoliciesFirewallAssociationArgs{
    						Domains: cdn.FrontdoorSecurityPolicySecurityPoliciesFirewallAssociationDomainArray{
    							&cdn.FrontdoorSecurityPolicySecurityPoliciesFirewallAssociationDomainArgs{
    								CdnFrontdoorDomainId: exampleFrontdoorCustomDomain.ID(),
    							},
    						},
    						PatternsToMatch: pulumi.String("/*"),
    					},
    				},
    			},
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Azure = Pulumi.Azure;
    
    return await Deployment.RunAsync(() => 
    {
        var example = new Azure.Core.ResourceGroup("example", new()
        {
            Name = "example-resource-group",
            Location = "West Europe",
        });
    
        var exampleZone = new Azure.Dns.Zone("example", new()
        {
            Name = "fabrikam.com",
            ResourceGroupName = example.Name,
        });
    
        var exampleFrontdoorProfile = new Azure.Cdn.FrontdoorProfile("example", new()
        {
            Name = "example-cdn-frontdoor-profile",
            ResourceGroupName = example.Name,
            SkuName = "Standard_AzureFrontDoor",
        });
    
        var exampleFrontdoorEndpoint = new Azure.Cdn.FrontdoorEndpoint("example", new()
        {
            Name = "example-cdn-frontdoor-endpoint",
            CdnFrontdoorProfileId = exampleFrontdoorProfile.Id,
        });
    
        var exampleFrontdoorOriginGroup = new Azure.Cdn.FrontdoorOriginGroup("example", new()
        {
            Name = "example-cdn-frontdoor-origin-group",
            CdnFrontdoorProfileId = exampleFrontdoorProfile.Id,
            LoadBalancing = null,
        });
    
        var exampleFrontdoorOrigin = new Azure.Cdn.FrontdoorOrigin("example", new()
        {
            Name = "example-cdn-frontdoor-origin",
            CdnFrontdoorOriginGroupId = exampleFrontdoorOriginGroup.Id,
            HostName = "contoso.fabrikam.com",
            CertificateNameCheckEnabled = false,
        });
    
        var exampleFrontdoorCustomDomain = new Azure.Cdn.FrontdoorCustomDomain("example", new()
        {
            Name = "example-cdn-frontdoor-custom-domain",
            CdnFrontdoorProfileId = exampleFrontdoorProfile.Id,
            DnsZoneId = exampleZone.Id,
            HostName = exampleFrontdoorOrigin.HostName,
            Tls = new Azure.Cdn.Inputs.FrontdoorCustomDomainTlsArgs
            {
                CertificateType = "ManagedCertificate",
                MinimumVersion = "TLS12",
            },
        });
    
        var exampleFrontdoorRoute = new Azure.Cdn.FrontdoorRoute("example", new()
        {
            Name = "example-cdn-frontdoor-route",
            CdnFrontdoorEndpointId = exampleFrontdoorEndpoint.Id,
            CdnFrontdoorOriginGroupId = exampleFrontdoorOriginGroup.Id,
            CdnFrontdoorOriginIds = new[]
            {
                exampleFrontdoorOrigin.Id,
            },
            CdnFrontdoorCustomDomainIds = new[]
            {
                exampleFrontdoorCustomDomain.Id,
            },
            PatternsToMatches = new[]
            {
                "/*",
            },
            SupportedProtocols = new[]
            {
                "Http",
                "Https",
            },
        });
    
        var exampleFrontdoorFirewallPolicy = new Azure.Cdn.FrontdoorFirewallPolicy("example", new()
        {
            Name = "examplecdnfrontdoorfirewallpolicy",
            ResourceGroupName = example.Name,
            SkuName = exampleFrontdoorProfile.SkuName,
            Mode = "Prevention",
        });
    
        var exampleFrontdoorSecurityPolicy = new Azure.Cdn.FrontdoorSecurityPolicy("example", new()
        {
            Name = "example-cdn-frontdoor-security-policy",
            CdnFrontdoorProfileId = exampleFrontdoorProfile.Id,
            SecurityPolicies = new Azure.Cdn.Inputs.FrontdoorSecurityPolicySecurityPoliciesArgs
            {
                Firewall = new Azure.Cdn.Inputs.FrontdoorSecurityPolicySecurityPoliciesFirewallArgs
                {
                    CdnFrontdoorFirewallPolicyId = exampleFrontdoorFirewallPolicy.Id,
                    Association = new Azure.Cdn.Inputs.FrontdoorSecurityPolicySecurityPoliciesFirewallAssociationArgs
                    {
                        Domains = new[]
                        {
                            new Azure.Cdn.Inputs.FrontdoorSecurityPolicySecurityPoliciesFirewallAssociationDomainArgs
                            {
                                CdnFrontdoorDomainId = exampleFrontdoorCustomDomain.Id,
                            },
                        },
                        PatternsToMatch = "/*",
                    },
                },
            },
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.azure.core.ResourceGroup;
    import com.pulumi.azure.core.ResourceGroupArgs;
    import com.pulumi.azure.dns.Zone;
    import com.pulumi.azure.dns.ZoneArgs;
    import com.pulumi.azure.cdn.FrontdoorProfile;
    import com.pulumi.azure.cdn.FrontdoorProfileArgs;
    import com.pulumi.azure.cdn.FrontdoorEndpoint;
    import com.pulumi.azure.cdn.FrontdoorEndpointArgs;
    import com.pulumi.azure.cdn.FrontdoorOriginGroup;
    import com.pulumi.azure.cdn.FrontdoorOriginGroupArgs;
    import com.pulumi.azure.cdn.inputs.FrontdoorOriginGroupLoadBalancingArgs;
    import com.pulumi.azure.cdn.FrontdoorOrigin;
    import com.pulumi.azure.cdn.FrontdoorOriginArgs;
    import com.pulumi.azure.cdn.FrontdoorCustomDomain;
    import com.pulumi.azure.cdn.FrontdoorCustomDomainArgs;
    import com.pulumi.azure.cdn.inputs.FrontdoorCustomDomainTlsArgs;
    import com.pulumi.azure.cdn.FrontdoorRoute;
    import com.pulumi.azure.cdn.FrontdoorRouteArgs;
    import com.pulumi.azure.cdn.FrontdoorFirewallPolicy;
    import com.pulumi.azure.cdn.FrontdoorFirewallPolicyArgs;
    import com.pulumi.azure.cdn.FrontdoorSecurityPolicy;
    import com.pulumi.azure.cdn.FrontdoorSecurityPolicyArgs;
    import com.pulumi.azure.cdn.inputs.FrontdoorSecurityPolicySecurityPoliciesArgs;
    import com.pulumi.azure.cdn.inputs.FrontdoorSecurityPolicySecurityPoliciesFirewallArgs;
    import com.pulumi.azure.cdn.inputs.FrontdoorSecurityPolicySecurityPoliciesFirewallAssociationArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var example = new ResourceGroup("example", ResourceGroupArgs.builder()
                .name("example-resource-group")
                .location("West Europe")
                .build());
    
            var exampleZone = new Zone("exampleZone", ZoneArgs.builder()
                .name("fabrikam.com")
                .resourceGroupName(example.name())
                .build());
    
            var exampleFrontdoorProfile = new FrontdoorProfile("exampleFrontdoorProfile", FrontdoorProfileArgs.builder()
                .name("example-cdn-frontdoor-profile")
                .resourceGroupName(example.name())
                .skuName("Standard_AzureFrontDoor")
                .build());
    
            var exampleFrontdoorEndpoint = new FrontdoorEndpoint("exampleFrontdoorEndpoint", FrontdoorEndpointArgs.builder()
                .name("example-cdn-frontdoor-endpoint")
                .cdnFrontdoorProfileId(exampleFrontdoorProfile.id())
                .build());
    
            var exampleFrontdoorOriginGroup = new FrontdoorOriginGroup("exampleFrontdoorOriginGroup", FrontdoorOriginGroupArgs.builder()
                .name("example-cdn-frontdoor-origin-group")
                .cdnFrontdoorProfileId(exampleFrontdoorProfile.id())
                .loadBalancing(FrontdoorOriginGroupLoadBalancingArgs.builder()
                    .build())
                .build());
    
            var exampleFrontdoorOrigin = new FrontdoorOrigin("exampleFrontdoorOrigin", FrontdoorOriginArgs.builder()
                .name("example-cdn-frontdoor-origin")
                .cdnFrontdoorOriginGroupId(exampleFrontdoorOriginGroup.id())
                .hostName("contoso.fabrikam.com")
                .certificateNameCheckEnabled(false)
                .build());
    
            var exampleFrontdoorCustomDomain = new FrontdoorCustomDomain("exampleFrontdoorCustomDomain", FrontdoorCustomDomainArgs.builder()
                .name("example-cdn-frontdoor-custom-domain")
                .cdnFrontdoorProfileId(exampleFrontdoorProfile.id())
                .dnsZoneId(exampleZone.id())
                .hostName(exampleFrontdoorOrigin.hostName())
                .tls(FrontdoorCustomDomainTlsArgs.builder()
                    .certificateType("ManagedCertificate")
                    .minimumVersion("TLS12")
                    .build())
                .build());
    
            var exampleFrontdoorRoute = new FrontdoorRoute("exampleFrontdoorRoute", FrontdoorRouteArgs.builder()
                .name("example-cdn-frontdoor-route")
                .cdnFrontdoorEndpointId(exampleFrontdoorEndpoint.id())
                .cdnFrontdoorOriginGroupId(exampleFrontdoorOriginGroup.id())
                .cdnFrontdoorOriginIds(exampleFrontdoorOrigin.id())
                .cdnFrontdoorCustomDomainIds(exampleFrontdoorCustomDomain.id())
                .patternsToMatches("/*")
                .supportedProtocols(            
                    "Http",
                    "Https")
                .build());
    
            var exampleFrontdoorFirewallPolicy = new FrontdoorFirewallPolicy("exampleFrontdoorFirewallPolicy", FrontdoorFirewallPolicyArgs.builder()
                .name("examplecdnfrontdoorfirewallpolicy")
                .resourceGroupName(example.name())
                .skuName(exampleFrontdoorProfile.skuName())
                .mode("Prevention")
                .build());
    
            var exampleFrontdoorSecurityPolicy = new FrontdoorSecurityPolicy("exampleFrontdoorSecurityPolicy", FrontdoorSecurityPolicyArgs.builder()
                .name("example-cdn-frontdoor-security-policy")
                .cdnFrontdoorProfileId(exampleFrontdoorProfile.id())
                .securityPolicies(FrontdoorSecurityPolicySecurityPoliciesArgs.builder()
                    .firewall(FrontdoorSecurityPolicySecurityPoliciesFirewallArgs.builder()
                        .cdnFrontdoorFirewallPolicyId(exampleFrontdoorFirewallPolicy.id())
                        .association(FrontdoorSecurityPolicySecurityPoliciesFirewallAssociationArgs.builder()
                            .domains(FrontdoorSecurityPolicySecurityPoliciesFirewallAssociationDomainArgs.builder()
                                .cdnFrontdoorDomainId(exampleFrontdoorCustomDomain.id())
                                .build())
                            .patternsToMatch("/*")
                            .build())
                        .build())
                    .build())
                .build());
    
        }
    }
    
    resources:
      example:
        type: azure:core:ResourceGroup
        properties:
          name: example-resource-group
          location: West Europe
      exampleZone:
        type: azure:dns:Zone
        name: example
        properties:
          name: fabrikam.com
          resourceGroupName: ${example.name}
      exampleFrontdoorProfile:
        type: azure:cdn:FrontdoorProfile
        name: example
        properties:
          name: example-cdn-frontdoor-profile
          resourceGroupName: ${example.name}
          skuName: Standard_AzureFrontDoor
      exampleFrontdoorEndpoint:
        type: azure:cdn:FrontdoorEndpoint
        name: example
        properties:
          name: example-cdn-frontdoor-endpoint
          cdnFrontdoorProfileId: ${exampleFrontdoorProfile.id}
      exampleFrontdoorOriginGroup:
        type: azure:cdn:FrontdoorOriginGroup
        name: example
        properties:
          name: example-cdn-frontdoor-origin-group
          cdnFrontdoorProfileId: ${exampleFrontdoorProfile.id}
          loadBalancing: {}
      exampleFrontdoorOrigin:
        type: azure:cdn:FrontdoorOrigin
        name: example
        properties:
          name: example-cdn-frontdoor-origin
          cdnFrontdoorOriginGroupId: ${exampleFrontdoorOriginGroup.id}
          hostName: contoso.fabrikam.com
          certificateNameCheckEnabled: false
      exampleFrontdoorCustomDomain:
        type: azure:cdn:FrontdoorCustomDomain
        name: example
        properties:
          name: example-cdn-frontdoor-custom-domain
          cdnFrontdoorProfileId: ${exampleFrontdoorProfile.id}
          dnsZoneId: ${exampleZone.id}
          hostName: ${exampleFrontdoorOrigin.hostName}
          tls:
            certificateType: ManagedCertificate
            minimumVersion: TLS12
      exampleFrontdoorRoute:
        type: azure:cdn:FrontdoorRoute
        name: example
        properties:
          name: example-cdn-frontdoor-route
          cdnFrontdoorEndpointId: ${exampleFrontdoorEndpoint.id}
          cdnFrontdoorOriginGroupId: ${exampleFrontdoorOriginGroup.id}
          cdnFrontdoorOriginIds:
            - ${exampleFrontdoorOrigin.id}
          cdnFrontdoorCustomDomainIds:
            - ${exampleFrontdoorCustomDomain.id}
          patternsToMatches:
            - /*
          supportedProtocols:
            - Http
            - Https
      exampleFrontdoorFirewallPolicy:
        type: azure:cdn:FrontdoorFirewallPolicy
        name: example
        properties:
          name: examplecdnfrontdoorfirewallpolicy
          resourceGroupName: ${example.name}
          skuName: ${exampleFrontdoorProfile.skuName}
          mode: Prevention
      exampleFrontdoorSecurityPolicy:
        type: azure:cdn:FrontdoorSecurityPolicy
        name: example
        properties:
          name: example-cdn-frontdoor-security-policy
          cdnFrontdoorProfileId: ${exampleFrontdoorProfile.id}
          securityPolicies:
            firewall:
              cdnFrontdoorFirewallPolicyId: ${exampleFrontdoorFirewallPolicy.id}
              association:
                domains:
                  - cdnFrontdoorDomainId: ${exampleFrontdoorCustomDomain.id}
                patternsToMatch: /*
    
    pulumi {
      required_providers {
        azure = {
          source = "pulumi/azure"
        }
      }
    }
    
    resource "azure_core_resourcegroup" "example" {
      name     = "example-resource-group"
      location = "West Europe"
    }
    resource "azure_dns_zone" "example" {
      name                = "fabrikam.com"
      resource_group_name = azure_core_resourcegroup.example.name
    }
    resource "azure_cdn_frontdoorprofile" "example" {
      name                = "example-cdn-frontdoor-profile"
      resource_group_name = azure_core_resourcegroup.example.name
      sku_name            = "Standard_AzureFrontDoor"
    }
    resource "azure_cdn_frontdoorendpoint" "example" {
      name                     = "example-cdn-frontdoor-endpoint"
      cdn_frontdoor_profile_id = azure_cdn_frontdoorprofile.example.id
    }
    resource "azure_cdn_frontdoororigingroup" "example" {
      name                     = "example-cdn-frontdoor-origin-group"
      cdn_frontdoor_profile_id = azure_cdn_frontdoorprofile.example.id
      load_balancing           = {}
    }
    resource "azure_cdn_frontdoororigin" "example" {
      name                           = "example-cdn-frontdoor-origin"
      cdn_frontdoor_origin_group_id  = azure_cdn_frontdoororigingroup.example.id
      host_name                      = "contoso.fabrikam.com"
      certificate_name_check_enabled = false
    }
    resource "azure_cdn_frontdoorcustomdomain" "example" {
      name                     = "example-cdn-frontdoor-custom-domain"
      cdn_frontdoor_profile_id = azure_cdn_frontdoorprofile.example.id
      dns_zone_id              = azure_dns_zone.example.id
      host_name                = azure_cdn_frontdoororigin.example.host_name
      tls = {
        certificate_type = "ManagedCertificate"
        minimum_version  = "TLS12"
      }
    }
    resource "azure_cdn_frontdoorroute" "example" {
      name                            = "example-cdn-frontdoor-route"
      cdn_frontdoor_endpoint_id       = azure_cdn_frontdoorendpoint.example.id
      cdn_frontdoor_origin_group_id   = azure_cdn_frontdoororigingroup.example.id
      cdn_frontdoor_origin_ids        = [azure_cdn_frontdoororigin.example.id]
      cdn_frontdoor_custom_domain_ids = [azure_cdn_frontdoorcustomdomain.example.id]
      patterns_to_matches             = ["/*"]
      supported_protocols             = ["Http", "Https"]
    }
    resource "azure_cdn_frontdoorfirewallpolicy" "example" {
      name                = "examplecdnfrontdoorfirewallpolicy"
      resource_group_name = azure_core_resourcegroup.example.name
      sku_name            = azure_cdn_frontdoorprofile.example.sku_name
      mode                = "Prevention"
    }
    resource "azure_cdn_frontdoorsecuritypolicy" "example" {
      name                     = "example-cdn-frontdoor-security-policy"
      cdn_frontdoor_profile_id = azure_cdn_frontdoorprofile.example.id
      security_policies = {
        firewall = {
          cdn_frontdoor_firewall_policy_id = azure_cdn_frontdoorfirewallpolicy.example.id
          association = {
            domains = [{
              "cdnFrontdoorDomainId" = azure_cdn_frontdoorcustomdomain.example.id
            }]
            patterns_to_match = "/*"
          }
        }
      }
    }
    

    Example DNS Auth TXT Record Usage

    The name of your DNS TXT record should be in the format of _dnsauth.<your_subdomain>. So, for example, if we use the hostName in the example usage above you would create a DNS TXT record with the name of _dnsauth.contoso which contains the value of the Front Door Custom Domains validationToken field. See the product documentation for more information.

    Note: Domain ownership validation is performed asynchronously by the Azure Front Door service (the domain typically transitions through states like Submitting and Pending before becoming Approved). If validation appears to be taking longer than expected, refer to the Azure Front Door documentation on domain validation and domain validation states.

    Note: Azure Front Door custom domain operations are currently gated by an internal service-side validation and backend synchronization process. While that process is running, the service can reject otherwise valid follow-up write operations until the custom domain reaches an approved state, which can make create, update, and delete operations take significantly longer than expected.

    import * as pulumi from "@pulumi/pulumi";
    import * as azure from "@pulumi/azure";
    import * as std from "@pulumi/std";
    
    const example = new azure.dns.TxtRecord("example", {
        name: std.split({
            separator: ".",
            text: exampleAzurermCdnFrontdoorCustomDomain.hostName,
        }).then(invoke => std.join({
            separator: ".",
            input: [
                "_dnsauth",
                invoke.result?.[0],
            ],
        })).then(invoke => invoke.result),
        zoneName: exampleAzurermDnsZone.name,
        resourceGroupName: exampleAzurermResourceGroup.name,
        ttl: 3600,
        records: [{
            value: exampleAzurermCdnFrontdoorCustomDomain.validationToken,
        }],
    });
    
    import pulumi
    import pulumi_azure as azure
    import pulumi_std as std
    
    example = azure.dns.TxtRecord("example",
        name=std.join(separator=".",
            input=[
                "_dnsauth",
                std.split(separator=".",
                    text=example_azurerm_cdn_frontdoor_custom_domain["hostName"]).result[0],
            ]).result,
        zone_name=example_azurerm_dns_zone["name"],
        resource_group_name=example_azurerm_resource_group["name"],
        ttl=3600,
        records=[{
            "value": example_azurerm_cdn_frontdoor_custom_domain["validationToken"],
        }])
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/dns"
    	"github.com/pulumi/pulumi-std/sdk/go/std"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		invokeJoin, err := std.Join(ctx, &std.JoinArgs{
    			Separator: ".",
    			Input: []interface{}{
    				"_dnsauth",
    				std.Split(ctx, &std.SplitArgs{
    					Separator: ".",
    					Text:      exampleAzurermCdnFrontdoorCustomDomain.HostName,
    				}, nil).Result[0],
    			},
    		}, nil)
    		if err != nil {
    			return err
    		}
    		_, err = dns.NewTxtRecord(ctx, "example", &dns.TxtRecordArgs{
    			Name:              pulumi.String(invokeJoin.Result),
    			ZoneName:          pulumi.Any(exampleAzurermDnsZone.Name),
    			ResourceGroupName: pulumi.Any(exampleAzurermResourceGroup.Name),
    			Ttl:               pulumi.Int(3600),
    			Records: dns.TxtRecordRecordArray{
    				&dns.TxtRecordRecordArgs{
    					Value: pulumi.Any(exampleAzurermCdnFrontdoorCustomDomain.ValidationToken),
    				},
    			},
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Azure = Pulumi.Azure;
    using Std = Pulumi.Std;
    
    return await Deployment.RunAsync(() => 
    {
        var example = new Azure.Dns.TxtRecord("example", new()
        {
            Name = Std.Split.Invoke(new()
            {
                Separator = ".",
                Text = exampleAzurermCdnFrontdoorCustomDomain.HostName,
            }).Apply(invoke => Std.Join.Invoke(new()
            {
                Separator = ".",
                Input = new[]
                {
                    "_dnsauth",
                    invoke.Result[0],
                },
            })).Apply(invoke => invoke.Result),
            ZoneName = exampleAzurermDnsZone.Name,
            ResourceGroupName = exampleAzurermResourceGroup.Name,
            Ttl = 3600,
            Records = new[]
            {
                new Azure.Dns.Inputs.TxtRecordRecordArgs
                {
                    Value = exampleAzurermCdnFrontdoorCustomDomain.ValidationToken,
                },
            },
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.azure.dns.TxtRecord;
    import com.pulumi.azure.dns.TxtRecordArgs;
    import com.pulumi.azure.dns.inputs.TxtRecordRecordArgs;
    import com.pulumi.std.StdFunctions;
    import com.pulumi.std.inputs.SplitArgs;
    import com.pulumi.std.inputs.JoinArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var example = new TxtRecord("example", TxtRecordArgs.builder()
                .name(StdFunctions.join(JoinArgs.builder()
                    .separator(".")
                    .input(                
                        "_dnsauth",
                        StdFunctions.split(SplitArgs.builder()
                            .separator(".")
                            .text(exampleAzurermCdnFrontdoorCustomDomain.hostName())
                            .build()).result()[0])
                    .build()).result())
                .zoneName(exampleAzurermDnsZone.name())
                .resourceGroupName(exampleAzurermResourceGroup.name())
                .ttl(3600)
                .records(TxtRecordRecordArgs.builder()
                    .value(exampleAzurermCdnFrontdoorCustomDomain.validationToken())
                    .build())
                .build());
    
        }
    }
    
    resources:
      example:
        type: azure:dns:TxtRecord
        properties:
          name:
            fn::invoke:
              function: std:join
              arguments:
                separator: .
                input:
                  - _dnsauth
                  - fn::invoke:
                      function: std:split
                      arguments:
                        separator: .
                        text: ${exampleAzurermCdnFrontdoorCustomDomain.hostName}
                      return: result[0]
              return: result
          zoneName: ${exampleAzurermDnsZone.name}
          resourceGroupName: ${exampleAzurermResourceGroup.name}
          ttl: 3600
          records:
            - value: ${exampleAzurermCdnFrontdoorCustomDomain.validationToken}
    
    pulumi {
      required_providers {
        azure = {
          source = "pulumi/azure"
        }
        std = {
          source = "pulumi/std"
        }
      }
    }
    
    resource "azure_dns_txtrecord" "example" {
      name                = join(".", ["_dnsauth", split(".", exampleAzurermCdnFrontdoorCustomDomain.hostName)[0]])
      zone_name           = exampleAzurermDnsZone.name
      resource_group_name = exampleAzurermResourceGroup.name
      ttl                 = 3600
      records {
        value = exampleAzurermCdnFrontdoorCustomDomain.validationToken
      }
    }
    

    Example CNAME Record Usage

    Note: When managing the CNAME record using Terraform, you may need to ensure your Custom Domain is associated with a Front Door Route (and any applicable Security Policy) before creating the CNAME record. This example uses dependsOn to enforce that ordering.

    import * as pulumi from "@pulumi/pulumi";
    import * as azure from "@pulumi/azure";
    import * as std from "@pulumi/std";
    
    const example = new azure.dns.CNameRecord("example", {
        name: std.split({
            separator: ".",
            text: exampleAzurermCdnFrontdoorCustomDomain.hostName,
        }).then(invoke => invoke.result?.[0]),
        zoneName: exampleAzurermDnsZone.name,
        resourceGroupName: exampleAzurermResourceGroup.name,
        ttl: 3600,
        record: exampleAzurermCdnFrontdoorEndpoint.hostName,
    }, {
        dependsOn: [
            exampleAzurermCdnFrontdoorRoute,
            exampleAzurermCdnFrontdoorSecurityPolicy,
        ],
    });
    
    import pulumi
    import pulumi_azure as azure
    import pulumi_std as std
    
    example = azure.dns.CNameRecord("example",
        name=std.split(separator=".",
            text=example_azurerm_cdn_frontdoor_custom_domain["hostName"]).result[0],
        zone_name=example_azurerm_dns_zone["name"],
        resource_group_name=example_azurerm_resource_group["name"],
        ttl=3600,
        record=example_azurerm_cdn_frontdoor_endpoint["hostName"],
        opts = pulumi.ResourceOptions(depends_on=[
                example_azurerm_cdn_frontdoor_route,
                example_azurerm_cdn_frontdoor_security_policy,
            ]))
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/dns"
    	"github.com/pulumi/pulumi-std/sdk/go/std"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		invokeSplit, err := std.Split(ctx, &std.SplitArgs{
    			Separator: ".",
    			Text:      exampleAzurermCdnFrontdoorCustomDomain.HostName,
    		}, nil)
    		if err != nil {
    			return err
    		}
    		_, err = dns.NewCNameRecord(ctx, "example", &dns.CNameRecordArgs{
    			Name:              pulumi.String(invokeSplit.Result[0]),
    			ZoneName:          pulumi.Any(exampleAzurermDnsZone.Name),
    			ResourceGroupName: pulumi.Any(exampleAzurermResourceGroup.Name),
    			Ttl:               pulumi.Int(3600),
    			Record:            pulumi.Any(exampleAzurermCdnFrontdoorEndpoint.HostName),
    		}, pulumi.DependsOn([]pulumi.Resource{
    			exampleAzurermCdnFrontdoorRoute,
    			exampleAzurermCdnFrontdoorSecurityPolicy,
    		}))
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Azure = Pulumi.Azure;
    using Std = Pulumi.Std;
    
    return await Deployment.RunAsync(() => 
    {
        var example = new Azure.Dns.CNameRecord("example", new()
        {
            Name = Std.Split.Invoke(new()
            {
                Separator = ".",
                Text = exampleAzurermCdnFrontdoorCustomDomain.HostName,
            }).Apply(invoke => invoke.Result[0]),
            ZoneName = exampleAzurermDnsZone.Name,
            ResourceGroupName = exampleAzurermResourceGroup.Name,
            Ttl = 3600,
            Record = exampleAzurermCdnFrontdoorEndpoint.HostName,
        }, new CustomResourceOptions
        {
            DependsOn =
            {
                exampleAzurermCdnFrontdoorRoute,
                exampleAzurermCdnFrontdoorSecurityPolicy,
            },
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.azure.dns.CNameRecord;
    import com.pulumi.azure.dns.CNameRecordArgs;
    import com.pulumi.std.StdFunctions;
    import com.pulumi.std.inputs.SplitArgs;
    import com.pulumi.resources.CustomResourceOptions;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var example = new CNameRecord("example", CNameRecordArgs.builder()
                .name(StdFunctions.split(SplitArgs.builder()
                    .separator(".")
                    .text(exampleAzurermCdnFrontdoorCustomDomain.hostName())
                    .build()).result()[0])
                .zoneName(exampleAzurermDnsZone.name())
                .resourceGroupName(exampleAzurermResourceGroup.name())
                .ttl(3600)
                .record(exampleAzurermCdnFrontdoorEndpoint.hostName())
                .build(), CustomResourceOptions.builder()
                    .dependsOn(                
                        exampleAzurermCdnFrontdoorRoute,
                        exampleAzurermCdnFrontdoorSecurityPolicy)
                    .build());
    
        }
    }
    
    resources:
      example:
        type: azure:dns:CNameRecord
        properties:
          name:
            fn::invoke:
              function: std:split
              arguments:
                separator: .
                text: ${exampleAzurermCdnFrontdoorCustomDomain.hostName}
              return: result[0]
          zoneName: ${exampleAzurermDnsZone.name}
          resourceGroupName: ${exampleAzurermResourceGroup.name}
          ttl: 3600
          record: ${exampleAzurermCdnFrontdoorEndpoint.hostName}
        options:
          dependsOn:
            - ${exampleAzurermCdnFrontdoorRoute}
            - ${exampleAzurermCdnFrontdoorSecurityPolicy}
    
    pulumi {
      required_providers {
        azure = {
          source = "pulumi/azure"
        }
        std = {
          source = "pulumi/std"
        }
      }
    }
    
    resource "azure_dns_cnamerecord" "example" {
      depends_on          = [exampleAzurermCdnFrontdoorRoute, exampleAzurermCdnFrontdoorSecurityPolicy]
      name                = split(".", exampleAzurermCdnFrontdoorCustomDomain.hostName)[0]
      zone_name           = exampleAzurermDnsZone.name
      resource_group_name = exampleAzurermResourceGroup.name
      ttl                 = 3600
      record              = exampleAzurermCdnFrontdoorEndpoint.hostName
    }
    

    API Providers

    This resource uses the following Azure API Providers:

    • Microsoft.Cdn - 2025-04-15

    Create FrontdoorCustomDomain Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new FrontdoorCustomDomain(name: string, args: FrontdoorCustomDomainArgs, opts?: CustomResourceOptions);
    @overload
    def FrontdoorCustomDomain(resource_name: str,
                              args: FrontdoorCustomDomainArgs,
                              opts: Optional[ResourceOptions] = None)
    
    @overload
    def FrontdoorCustomDomain(resource_name: str,
                              opts: Optional[ResourceOptions] = None,
                              cdn_frontdoor_profile_id: Optional[str] = None,
                              host_name: Optional[str] = None,
                              tls: Optional[FrontdoorCustomDomainTlsArgs] = None,
                              dns_zone_id: Optional[str] = None,
                              name: Optional[str] = None)
    func NewFrontdoorCustomDomain(ctx *Context, name string, args FrontdoorCustomDomainArgs, opts ...ResourceOption) (*FrontdoorCustomDomain, error)
    public FrontdoorCustomDomain(string name, FrontdoorCustomDomainArgs args, CustomResourceOptions? opts = null)
    public FrontdoorCustomDomain(String name, FrontdoorCustomDomainArgs args)
    public FrontdoorCustomDomain(String name, FrontdoorCustomDomainArgs args, CustomResourceOptions options)
    
    type: azure:cdn:FrontdoorCustomDomain
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "azure_cdn_frontdoorcustomdomain" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args FrontdoorCustomDomainArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args FrontdoorCustomDomainArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args FrontdoorCustomDomainArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args FrontdoorCustomDomainArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args FrontdoorCustomDomainArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var frontdoorCustomDomainResource = new Azure.Cdn.FrontdoorCustomDomain("frontdoorCustomDomainResource", new()
    {
        CdnFrontdoorProfileId = "string",
        HostName = "string",
        Tls = new Azure.Cdn.Inputs.FrontdoorCustomDomainTlsArgs
        {
            CdnFrontdoorSecretId = "string",
            CertificateType = "string",
            CipherSuite = new Azure.Cdn.Inputs.FrontdoorCustomDomainTlsCipherSuiteArgs
            {
                Type = "string",
                CustomCiphers = new Azure.Cdn.Inputs.FrontdoorCustomDomainTlsCipherSuiteCustomCiphersArgs
                {
                    Tls12s = new[]
                    {
                        "string",
                    },
                    Tls13s = new[]
                    {
                        "string",
                    },
                },
            },
            MinimumVersion = "string",
        },
        DnsZoneId = "string",
        Name = "string",
    });
    
    example, err := cdn.NewFrontdoorCustomDomain(ctx, "frontdoorCustomDomainResource", &cdn.FrontdoorCustomDomainArgs{
    	CdnFrontdoorProfileId: pulumi.String("string"),
    	HostName:              pulumi.String("string"),
    	Tls: &cdn.FrontdoorCustomDomainTlsArgs{
    		CdnFrontdoorSecretId: pulumi.String("string"),
    		CertificateType:      pulumi.String("string"),
    		CipherSuite: &cdn.FrontdoorCustomDomainTlsCipherSuiteArgs{
    			Type: pulumi.String("string"),
    			CustomCiphers: &cdn.FrontdoorCustomDomainTlsCipherSuiteCustomCiphersArgs{
    				Tls12s: pulumi.StringArray{
    					pulumi.String("string"),
    				},
    				Tls13s: pulumi.StringArray{
    					pulumi.String("string"),
    				},
    			},
    		},
    		MinimumVersion: pulumi.String("string"),
    	},
    	DnsZoneId: pulumi.String("string"),
    	Name:      pulumi.String("string"),
    })
    
    resource "azure_cdn_frontdoorcustomdomain" "frontdoorCustomDomainResource" {
      cdn_frontdoor_profile_id = "string"
      host_name                = "string"
      tls = {
        cdn_frontdoor_secret_id = "string"
        certificate_type        = "string"
        cipher_suite = {
          type = "string"
          custom_ciphers = {
            tls12s = ["string"]
            tls13s = ["string"]
          }
        }
        minimum_version = "string"
      }
      dns_zone_id = "string"
      name        = "string"
    }
    
    var frontdoorCustomDomainResource = new FrontdoorCustomDomain("frontdoorCustomDomainResource", FrontdoorCustomDomainArgs.builder()
        .cdnFrontdoorProfileId("string")
        .hostName("string")
        .tls(FrontdoorCustomDomainTlsArgs.builder()
            .cdnFrontdoorSecretId("string")
            .certificateType("string")
            .cipherSuite(FrontdoorCustomDomainTlsCipherSuiteArgs.builder()
                .type("string")
                .customCiphers(FrontdoorCustomDomainTlsCipherSuiteCustomCiphersArgs.builder()
                    .tls12s("string")
                    .tls13s("string")
                    .build())
                .build())
            .minimumVersion("string")
            .build())
        .dnsZoneId("string")
        .name("string")
        .build());
    
    frontdoor_custom_domain_resource = azure.cdn.FrontdoorCustomDomain("frontdoorCustomDomainResource",
        cdn_frontdoor_profile_id="string",
        host_name="string",
        tls={
            "cdn_frontdoor_secret_id": "string",
            "certificate_type": "string",
            "cipher_suite": {
                "type": "string",
                "custom_ciphers": {
                    "tls12s": ["string"],
                    "tls13s": ["string"],
                },
            },
            "minimum_version": "string",
        },
        dns_zone_id="string",
        name="string")
    
    const frontdoorCustomDomainResource = new azure.cdn.FrontdoorCustomDomain("frontdoorCustomDomainResource", {
        cdnFrontdoorProfileId: "string",
        hostName: "string",
        tls: {
            cdnFrontdoorSecretId: "string",
            certificateType: "string",
            cipherSuite: {
                type: "string",
                customCiphers: {
                    tls12s: ["string"],
                    tls13s: ["string"],
                },
            },
            minimumVersion: "string",
        },
        dnsZoneId: "string",
        name: "string",
    });
    
    type: azure:cdn:FrontdoorCustomDomain
    properties:
        cdnFrontdoorProfileId: string
        dnsZoneId: string
        hostName: string
        name: string
        tls:
            cdnFrontdoorSecretId: string
            certificateType: string
            cipherSuite:
                customCiphers:
                    tls12s:
                        - string
                    tls13s:
                        - string
                type: string
            minimumVersion: string
    

    FrontdoorCustomDomain Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The FrontdoorCustomDomain resource accepts the following input properties:

    CdnFrontdoorProfileId string
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    HostName string

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    Tls FrontdoorCustomDomainTls
    A tls block as defined below.
    DnsZoneId string

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    Name string

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    CdnFrontdoorProfileId string
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    HostName string

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    Tls FrontdoorCustomDomainTlsArgs
    A tls block as defined below.
    DnsZoneId string

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    Name string

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    cdn_frontdoor_profile_id string
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    host_name string

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    tls object
    A tls block as defined below.
    dns_zone_id string

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    name string

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    cdnFrontdoorProfileId String
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    hostName String

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    tls FrontdoorCustomDomainTls
    A tls block as defined below.
    dnsZoneId String

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    name String

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    cdnFrontdoorProfileId string
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    hostName string

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    tls FrontdoorCustomDomainTls
    A tls block as defined below.
    dnsZoneId string

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    name string

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    cdn_frontdoor_profile_id str
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    host_name str

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    tls FrontdoorCustomDomainTlsArgs
    A tls block as defined below.
    dns_zone_id str

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    name str

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    cdnFrontdoorProfileId String
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    hostName String

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    tls Property Map
    A tls block as defined below.
    dnsZoneId String

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    name String

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the FrontdoorCustomDomain resource produces the following output properties:

    ExpirationDate string
    The date and time that the token expires.
    Id string
    The provider-assigned unique ID for this managed resource.
    ValidationToken string
    Challenge used for DNS TXT record or file based validation.
    ExpirationDate string
    The date and time that the token expires.
    Id string
    The provider-assigned unique ID for this managed resource.
    ValidationToken string
    Challenge used for DNS TXT record or file based validation.
    expiration_date string
    The date and time that the token expires.
    id string
    The provider-assigned unique ID for this managed resource.
    validation_token string
    Challenge used for DNS TXT record or file based validation.
    expirationDate String
    The date and time that the token expires.
    id String
    The provider-assigned unique ID for this managed resource.
    validationToken String
    Challenge used for DNS TXT record or file based validation.
    expirationDate string
    The date and time that the token expires.
    id string
    The provider-assigned unique ID for this managed resource.
    validationToken string
    Challenge used for DNS TXT record or file based validation.
    expiration_date str
    The date and time that the token expires.
    id str
    The provider-assigned unique ID for this managed resource.
    validation_token str
    Challenge used for DNS TXT record or file based validation.
    expirationDate String
    The date and time that the token expires.
    id String
    The provider-assigned unique ID for this managed resource.
    validationToken String
    Challenge used for DNS TXT record or file based validation.

    Look up Existing FrontdoorCustomDomain Resource

    Get an existing FrontdoorCustomDomain resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

    public static get(name: string, id: Input<ID>, state?: FrontdoorCustomDomainState, opts?: CustomResourceOptions): FrontdoorCustomDomain
    @staticmethod
    def get(resource_name: str,
            id: str,
            opts: Optional[ResourceOptions] = None,
            cdn_frontdoor_profile_id: Optional[str] = None,
            dns_zone_id: Optional[str] = None,
            expiration_date: Optional[str] = None,
            host_name: Optional[str] = None,
            name: Optional[str] = None,
            tls: Optional[FrontdoorCustomDomainTlsArgs] = None,
            validation_token: Optional[str] = None) -> FrontdoorCustomDomain
    func GetFrontdoorCustomDomain(ctx *Context, name string, id IDInput, state *FrontdoorCustomDomainState, opts ...ResourceOption) (*FrontdoorCustomDomain, error)
    public static FrontdoorCustomDomain Get(string name, Input<string> id, FrontdoorCustomDomainState? state, CustomResourceOptions? opts = null)
    public static FrontdoorCustomDomain get(String name, Output<String> id, FrontdoorCustomDomainState state, CustomResourceOptions options)
    resources:  _:    type: azure:cdn:FrontdoorCustomDomain    get:      id: ${id}
    import {
      to = azure_cdn_frontdoorcustomdomain.example
      id = "${id}"
    }
    
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    resource_name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    The following state arguments are supported:
    CdnFrontdoorProfileId string
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    DnsZoneId string

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    ExpirationDate string
    The date and time that the token expires.
    HostName string

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    Name string

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    Tls FrontdoorCustomDomainTls
    A tls block as defined below.
    ValidationToken string
    Challenge used for DNS TXT record or file based validation.
    CdnFrontdoorProfileId string
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    DnsZoneId string

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    ExpirationDate string
    The date and time that the token expires.
    HostName string

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    Name string

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    Tls FrontdoorCustomDomainTlsArgs
    A tls block as defined below.
    ValidationToken string
    Challenge used for DNS TXT record or file based validation.
    cdn_frontdoor_profile_id string
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    dns_zone_id string

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    expiration_date string
    The date and time that the token expires.
    host_name string

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    name string

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    tls object
    A tls block as defined below.
    validation_token string
    Challenge used for DNS TXT record or file based validation.
    cdnFrontdoorProfileId String
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    dnsZoneId String

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    expirationDate String
    The date and time that the token expires.
    hostName String

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    name String

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    tls FrontdoorCustomDomainTls
    A tls block as defined below.
    validationToken String
    Challenge used for DNS TXT record or file based validation.
    cdnFrontdoorProfileId string
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    dnsZoneId string

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    expirationDate string
    The date and time that the token expires.
    hostName string

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    name string

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    tls FrontdoorCustomDomainTls
    A tls block as defined below.
    validationToken string
    Challenge used for DNS TXT record or file based validation.
    cdn_frontdoor_profile_id str
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    dns_zone_id str

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    expiration_date str
    The date and time that the token expires.
    host_name str

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    name str

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    tls FrontdoorCustomDomainTlsArgs
    A tls block as defined below.
    validation_token str
    Challenge used for DNS TXT record or file based validation.
    cdnFrontdoorProfileId String
    The ID of the Front Door Profile. Changing this forces a new resource to be created.
    dnsZoneId String

    The ID of the Azure DNS Zone which should be used for this Front Door Custom Domain.

    Note: If you are using Azure to host your DNS domains, you must delegate the domain provider's domain name system (DNS) to an Azure DNS Zone. For more information, see Delegate a domain to Azure DNS. Otherwise, if you're using your own domain provider to handle your DNS, you must validate the Front Door Custom Domain by creating the DNS TXT records manually.

    expirationDate String
    The date and time that the token expires.
    hostName String

    The host name of the domain. Changing this forces a new resource to be created.

    Note: The hostName field must be the FQDN of your domain (e.g. contoso.fabrikam.com).

    name String

    The name which should be used for this Front Door Custom Domain. Changing this forces a new resource to be created.

    Note: name must be between 2 and 260 characters in length, must begin with a letter or number, end with a letter or number, and contain only letters, numbers, and hyphens.

    tls Property Map
    A tls block as defined below.
    validationToken String
    Challenge used for DNS TXT record or file based validation.

    Supporting Types

    FrontdoorCustomDomainTls, FrontdoorCustomDomainTlsArgs

    CdnFrontdoorSecretId string

    Resource ID of the Front Door Secret.

    Note: cdnFrontdoorSecretId must be specified when certificateType is CustomerCertificate and must not be specified when certificateType is ManagedCertificate.

    CertificateType string

    Defines the source of the SSL certificate. Possible values are CustomerCertificate and ManagedCertificate. Defaults to ManagedCertificate.

    Note: It may take up to 15 minutes for the Front Door Service to validate the state and domain ownership of the Custom Domain.

    CipherSuite FrontdoorCustomDomainTlsCipherSuite
    A cipherSuite block as defined below.
    MinimumTlsVersion string

    Deprecated: minimumTlsVersion has been deprecated in favour of minimumVersion and will be removed in v5.0 of the AzureRM provider

    MinimumVersion string
    TLS protocol version that will be used for HTTPS. The only possible value is TLS12. Defaults to TLS12.
    CdnFrontdoorSecretId string

    Resource ID of the Front Door Secret.

    Note: cdnFrontdoorSecretId must be specified when certificateType is CustomerCertificate and must not be specified when certificateType is ManagedCertificate.

    CertificateType string

    Defines the source of the SSL certificate. Possible values are CustomerCertificate and ManagedCertificate. Defaults to ManagedCertificate.

    Note: It may take up to 15 minutes for the Front Door Service to validate the state and domain ownership of the Custom Domain.

    CipherSuite FrontdoorCustomDomainTlsCipherSuite
    A cipherSuite block as defined below.
    MinimumTlsVersion string

    Deprecated: minimumTlsVersion has been deprecated in favour of minimumVersion and will be removed in v5.0 of the AzureRM provider

    MinimumVersion string
    TLS protocol version that will be used for HTTPS. The only possible value is TLS12. Defaults to TLS12.
    cdn_frontdoor_secret_id string

    Resource ID of the Front Door Secret.

    Note: cdnFrontdoorSecretId must be specified when certificateType is CustomerCertificate and must not be specified when certificateType is ManagedCertificate.

    certificate_type string

    Defines the source of the SSL certificate. Possible values are CustomerCertificate and ManagedCertificate. Defaults to ManagedCertificate.

    Note: It may take up to 15 minutes for the Front Door Service to validate the state and domain ownership of the Custom Domain.

    cipher_suite object
    A cipherSuite block as defined below.
    minimum_tls_version string

    Deprecated: minimumTlsVersion has been deprecated in favour of minimumVersion and will be removed in v5.0 of the AzureRM provider

    minimum_version string
    TLS protocol version that will be used for HTTPS. The only possible value is TLS12. Defaults to TLS12.
    cdnFrontdoorSecretId String

    Resource ID of the Front Door Secret.

    Note: cdnFrontdoorSecretId must be specified when certificateType is CustomerCertificate and must not be specified when certificateType is ManagedCertificate.

    certificateType String

    Defines the source of the SSL certificate. Possible values are CustomerCertificate and ManagedCertificate. Defaults to ManagedCertificate.

    Note: It may take up to 15 minutes for the Front Door Service to validate the state and domain ownership of the Custom Domain.

    cipherSuite FrontdoorCustomDomainTlsCipherSuite
    A cipherSuite block as defined below.
    minimumTlsVersion String

    Deprecated: minimumTlsVersion has been deprecated in favour of minimumVersion and will be removed in v5.0 of the AzureRM provider

    minimumVersion String
    TLS protocol version that will be used for HTTPS. The only possible value is TLS12. Defaults to TLS12.
    cdnFrontdoorSecretId string

    Resource ID of the Front Door Secret.

    Note: cdnFrontdoorSecretId must be specified when certificateType is CustomerCertificate and must not be specified when certificateType is ManagedCertificate.

    certificateType string

    Defines the source of the SSL certificate. Possible values are CustomerCertificate and ManagedCertificate. Defaults to ManagedCertificate.

    Note: It may take up to 15 minutes for the Front Door Service to validate the state and domain ownership of the Custom Domain.

    cipherSuite FrontdoorCustomDomainTlsCipherSuite
    A cipherSuite block as defined below.
    minimumTlsVersion string

    Deprecated: minimumTlsVersion has been deprecated in favour of minimumVersion and will be removed in v5.0 of the AzureRM provider

    minimumVersion string
    TLS protocol version that will be used for HTTPS. The only possible value is TLS12. Defaults to TLS12.
    cdn_frontdoor_secret_id str

    Resource ID of the Front Door Secret.

    Note: cdnFrontdoorSecretId must be specified when certificateType is CustomerCertificate and must not be specified when certificateType is ManagedCertificate.

    certificate_type str

    Defines the source of the SSL certificate. Possible values are CustomerCertificate and ManagedCertificate. Defaults to ManagedCertificate.

    Note: It may take up to 15 minutes for the Front Door Service to validate the state and domain ownership of the Custom Domain.

    cipher_suite FrontdoorCustomDomainTlsCipherSuite
    A cipherSuite block as defined below.
    minimum_tls_version str

    Deprecated: minimumTlsVersion has been deprecated in favour of minimumVersion and will be removed in v5.0 of the AzureRM provider

    minimum_version str
    TLS protocol version that will be used for HTTPS. The only possible value is TLS12. Defaults to TLS12.
    cdnFrontdoorSecretId String

    Resource ID of the Front Door Secret.

    Note: cdnFrontdoorSecretId must be specified when certificateType is CustomerCertificate and must not be specified when certificateType is ManagedCertificate.

    certificateType String

    Defines the source of the SSL certificate. Possible values are CustomerCertificate and ManagedCertificate. Defaults to ManagedCertificate.

    Note: It may take up to 15 minutes for the Front Door Service to validate the state and domain ownership of the Custom Domain.

    cipherSuite Property Map
    A cipherSuite block as defined below.
    minimumTlsVersion String

    Deprecated: minimumTlsVersion has been deprecated in favour of minimumVersion and will be removed in v5.0 of the AzureRM provider

    minimumVersion String
    TLS protocol version that will be used for HTTPS. The only possible value is TLS12. Defaults to TLS12.

    FrontdoorCustomDomainTlsCipherSuite, FrontdoorCustomDomainTlsCipherSuiteArgs

    Type string
    The cipher suite set type. Possible values are Customized, TLS12_2022, and TLS12_2023.
    CustomCiphers FrontdoorCustomDomainTlsCipherSuiteCustomCiphers

    A customCiphers block as defined below.

    Note: The customCiphers block is required when type is set to Customized and must not be specified otherwise.

    Type string
    The cipher suite set type. Possible values are Customized, TLS12_2022, and TLS12_2023.
    CustomCiphers FrontdoorCustomDomainTlsCipherSuiteCustomCiphers

    A customCiphers block as defined below.

    Note: The customCiphers block is required when type is set to Customized and must not be specified otherwise.

    type string
    The cipher suite set type. Possible values are Customized, TLS12_2022, and TLS12_2023.
    custom_ciphers object

    A customCiphers block as defined below.

    Note: The customCiphers block is required when type is set to Customized and must not be specified otherwise.

    type String
    The cipher suite set type. Possible values are Customized, TLS12_2022, and TLS12_2023.
    customCiphers FrontdoorCustomDomainTlsCipherSuiteCustomCiphers

    A customCiphers block as defined below.

    Note: The customCiphers block is required when type is set to Customized and must not be specified otherwise.

    type string
    The cipher suite set type. Possible values are Customized, TLS12_2022, and TLS12_2023.
    customCiphers FrontdoorCustomDomainTlsCipherSuiteCustomCiphers

    A customCiphers block as defined below.

    Note: The customCiphers block is required when type is set to Customized and must not be specified otherwise.

    type str
    The cipher suite set type. Possible values are Customized, TLS12_2022, and TLS12_2023.
    custom_ciphers FrontdoorCustomDomainTlsCipherSuiteCustomCiphers

    A customCiphers block as defined below.

    Note: The customCiphers block is required when type is set to Customized and must not be specified otherwise.

    type String
    The cipher suite set type. Possible values are Customized, TLS12_2022, and TLS12_2023.
    customCiphers Property Map

    A customCiphers block as defined below.

    Note: The customCiphers block is required when type is set to Customized and must not be specified otherwise.

    FrontdoorCustomDomainTlsCipherSuiteCustomCiphers, FrontdoorCustomDomainTlsCipherSuiteCustomCiphersArgs

    Tls12s List<string>

    A set of TLS 1.2 cipher suites. Possible values are DHE_RSA_AES128_GCM_SHA256, DHE_RSA_AES256_GCM_SHA384, ECDHE_RSA_AES128_GCM_SHA256, ECDHE_RSA_AES128_SHA256, ECDHE_RSA_AES256_GCM_SHA384, and ECDHE_RSA_AES256_SHA384.

    Note: At least one TLS 1.2 cipher suite must be specified in tls12 when minimumVersion is TLS12 and type is Customized.

    Tls13s List<string>

    A set of TLS 1.3 cipher suites. Possible values are TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    Note: When tls13 is specified, it must include both TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    Tls12s []string

    A set of TLS 1.2 cipher suites. Possible values are DHE_RSA_AES128_GCM_SHA256, DHE_RSA_AES256_GCM_SHA384, ECDHE_RSA_AES128_GCM_SHA256, ECDHE_RSA_AES128_SHA256, ECDHE_RSA_AES256_GCM_SHA384, and ECDHE_RSA_AES256_SHA384.

    Note: At least one TLS 1.2 cipher suite must be specified in tls12 when minimumVersion is TLS12 and type is Customized.

    Tls13s []string

    A set of TLS 1.3 cipher suites. Possible values are TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    Note: When tls13 is specified, it must include both TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    tls12s list(string)

    A set of TLS 1.2 cipher suites. Possible values are DHE_RSA_AES128_GCM_SHA256, DHE_RSA_AES256_GCM_SHA384, ECDHE_RSA_AES128_GCM_SHA256, ECDHE_RSA_AES128_SHA256, ECDHE_RSA_AES256_GCM_SHA384, and ECDHE_RSA_AES256_SHA384.

    Note: At least one TLS 1.2 cipher suite must be specified in tls12 when minimumVersion is TLS12 and type is Customized.

    tls13s list(string)

    A set of TLS 1.3 cipher suites. Possible values are TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    Note: When tls13 is specified, it must include both TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    tls12s List<String>

    A set of TLS 1.2 cipher suites. Possible values are DHE_RSA_AES128_GCM_SHA256, DHE_RSA_AES256_GCM_SHA384, ECDHE_RSA_AES128_GCM_SHA256, ECDHE_RSA_AES128_SHA256, ECDHE_RSA_AES256_GCM_SHA384, and ECDHE_RSA_AES256_SHA384.

    Note: At least one TLS 1.2 cipher suite must be specified in tls12 when minimumVersion is TLS12 and type is Customized.

    tls13s List<String>

    A set of TLS 1.3 cipher suites. Possible values are TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    Note: When tls13 is specified, it must include both TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    tls12s string[]

    A set of TLS 1.2 cipher suites. Possible values are DHE_RSA_AES128_GCM_SHA256, DHE_RSA_AES256_GCM_SHA384, ECDHE_RSA_AES128_GCM_SHA256, ECDHE_RSA_AES128_SHA256, ECDHE_RSA_AES256_GCM_SHA384, and ECDHE_RSA_AES256_SHA384.

    Note: At least one TLS 1.2 cipher suite must be specified in tls12 when minimumVersion is TLS12 and type is Customized.

    tls13s string[]

    A set of TLS 1.3 cipher suites. Possible values are TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    Note: When tls13 is specified, it must include both TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    tls12s Sequence[str]

    A set of TLS 1.2 cipher suites. Possible values are DHE_RSA_AES128_GCM_SHA256, DHE_RSA_AES256_GCM_SHA384, ECDHE_RSA_AES128_GCM_SHA256, ECDHE_RSA_AES128_SHA256, ECDHE_RSA_AES256_GCM_SHA384, and ECDHE_RSA_AES256_SHA384.

    Note: At least one TLS 1.2 cipher suite must be specified in tls12 when minimumVersion is TLS12 and type is Customized.

    tls13s Sequence[str]

    A set of TLS 1.3 cipher suites. Possible values are TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    Note: When tls13 is specified, it must include both TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    tls12s List<String>

    A set of TLS 1.2 cipher suites. Possible values are DHE_RSA_AES128_GCM_SHA256, DHE_RSA_AES256_GCM_SHA384, ECDHE_RSA_AES128_GCM_SHA256, ECDHE_RSA_AES128_SHA256, ECDHE_RSA_AES256_GCM_SHA384, and ECDHE_RSA_AES256_SHA384.

    Note: At least one TLS 1.2 cipher suite must be specified in tls12 when minimumVersion is TLS12 and type is Customized.

    tls13s List<String>

    A set of TLS 1.3 cipher suites. Possible values are TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    Note: When tls13 is specified, it must include both TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384.

    Import

    A Front Door Custom Domain can be imported using the resource id, e.g.

    $ pulumi import azure:cdn/frontdoorCustomDomain:FrontdoorCustomDomain example /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/resourceGroup1/providers/Microsoft.Cdn/profiles/profile1/customDomains/customDomain1
    

    To learn more about importing existing cloud resources, see Importing resources.

    Package Details

    Repository
    Azure Classic pulumi/pulumi-azure
    License
    Apache-2.0
    Notes
    This Pulumi package is based on the azurerm Terraform Provider.
    azure logo

    We recommend using Azure Native.

    Viewing docs for Azure v6.38.0
    published on Wednesday, May 27, 2026 by Pulumi

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial