Azure DNS & Domains
Provider-specific DNS configuration and SSL certificate setup for Azure deployments.
Overview
Azure uses Azure DNS for domain management and Front Door for TLS certificate provisioning. Once nameservers point to Azure DNS, Front Door automatically validates domains and provisions managed TLS certificates — no manual DNS validation records are needed.
Step 1: Deploy Infrastructure
When baseDomain is configured, infra:deploy creates an Azure DNS zone automatically.
The CLI displays the Azure DNS zone nameservers after deployment.
Step 2: Find Azure DNS Nameservers
If you need to find the nameservers later:
- Go to the Azure Portal
- Search for "DNS zones"
- Click on your DNS zone (e.g.,
example.com) - The Overview page shows the Name server records (4 values)
- Copy all 4 nameservers (e.g.,
ns1-03.azure-dns.com,ns2-03.azure-dns.net, etc.)
Before You Switch: Existing Records
Skip this if your domain has no DNS records yet.
If it already has records at your current DNS provider (for example email sending or verification records), copy them into the Azure DNS zone before you change the nameservers (Portal > DNS zones > your domain > + Record set). After the switch, only records in Azure DNS resolve. Terraform leaves records you add by hand alone.
If the domain already pointed somewhere (an earlier deployment, a parking page), delete those old address records at the previous DNS provider after the switch. Some DNS resolvers keep asking the previous provider for a while, and while it still answers with the old addresses, they send part of your traffic there, including server-side calls from your own services.
Step 3: Update Domain Registrar
Go to your domain registrar (Namecheap, Cloudflare, GoDaddy, etc.):
- Find Nameservers or DNS settings
- Change to Custom nameservers
- Enter the 4 Azure DNS nameservers (one per field, no trailing dots)
- Save changes
Propagation: DNS changes take 15 minutes to 48 hours (usually under 1 hour).
SSL Certificates
Front Door provisions managed TLS certificates automatically once DNS is configured. No manual validation records are needed.
Checking Custom Domain Status
- Navigate to Front Door and CDN profiles in the portal
- Click your Front Door profile (e.g.,
{projectName}-{env}-fd) - Click Domains in the left sidebar
- Each custom domain shows:
- Domain validation state — should be
Approved - HTTPS certificate status — should be
Succeeded
- Domain validation state — should be
- If stuck on
Pending, ensure nameservers are correctly pointed to Azure DNS
Standard vs Premium SSL
- Standard: Front Door connects to public App Service endpoints, validates via FDID header
- Premium: Front Door connects via Private Link (no public endpoints needed)
Both tiers use Front Door Managed Certificates — auto-provisioned and auto-renewed.
What Terraform Manages
Once nameservers point to Azure DNS, Terraform handles everything else:
- CNAME records for Front Door endpoints
- TXT records for domain validation
- A records for apex domains
- TLS certificate provisioning via Front Door Managed Certificates
You only need to set nameservers once per domain. All other DNS records are created and managed by infra:deploy.
Domain Changes
Front Door custom domain host_name is ForceNew in Terraform (destroy + recreate). The deploy command handles this with three-phase auto-recovery:
- Targeted apply to remove route associations
- Full apply to replace custom domains
- Regenerate full config to re-associate routes
This handles domain changes without manual intervention.
Troubleshooting
Domain stuck on "Pending"
- Verify nameservers at your registrar match Azure DNS
- Check DNS propagation:
dig NS example.com +short - Wait for propagation (can take up to 48 hours)
- Redeploy:
npx tsdevstack infra:deploy --env dev
SKU Upgrade (Standard to Premium)
Upgrading from Standard to Premium triggers custom domain re-provisioning. This takes ~30-45 minutes and happens automatically during infra:deploy.