Tencent Cloud EdgeOne (TEO) DNS Authenticator plugin for Certbot (similar to certbot-dns-aliyun / certbot-dns-cloudflare), allowing automated issuance and renewal of Let's Encrypt SSL/TLS certificates (including wildcard certificates).
This plugin automates the process of completing dns-01 challenges by creating and subsequently removing _acme-challenge TXT records via the Tencent Cloud EdgeOne API.
- Automated DNS-01 Challenge: Automatically matches the corresponding EdgeOne Zone, creates verification TXT records, and cleans them up after ACME validation.
- Wildcard Certificate Support: Full support for single domains, multi-domains (SAN), and wildcard domains (e.g.,
*.example.com). - IDN / Punycode Support: Built-in support for internationalized domain names (Chinese, Japanese, etc.).
- Smart Zone Discovery & Caching: Progressively looks up parent domains to locate the EdgeOne Zone ID, with in-memory caching to minimize API requests.
- Customizable: Allows specifying a
zone-idexplicitly and configuring custom DNS propagation wait times.
In your virtual environment:
uv pip install certbot-dns-edgeoneOr install from source:
git clone https://github.com/hurole/certbot-dns-edgeone.git
cd certbot-dns-edgeone
# Create and activate virtual environment
uv venv
source .venv/bin/activate
# Install in editable mode
uv pip install -e .pip install certbot certbot-dns-edgeoneVerify that Certbot discovers the plugin:
certbot pluginsYou should see * dns-edgeone listed in the output:
* dns-edgeone
Description: Obtain certificates using a DNS TXT record (if you are using Tencent Cloud EdgeOne for DNS).
Interfaces: Authenticator, Plugin
Entry point: dns-edgeone = certbot_dns_edgeone.dns_edgeone:Authenticator
- Go to Tencent Cloud CAM Console - API Key Management to generate an API key (
SecretIdandSecretKey). - Ensure the user or role has the required EdgeOne (TEO) permissions (
QcloudTEOFullAccessor a custom policy grantingteo:DescribeZones,teo:CreateDnsRecord,teo:DescribeDnsRecords, andteo:DeleteDnsRecords). - Create a credentials INI file (e.g.,
~/.secrets/certbot/edgeone.ini):
# Tencent Cloud EdgeOne API credentials
dns_edgeone_secret_id = YOUR_TENCENTCLOUD_SECRET_ID
dns_edgeone_secret_key = YOUR_TENCENTCLOUD_SECRET_KEY
# Optional: STS Security Token (if using temporary credentials)
# dns_edgeone_token = your_sts_token
# Optional: Manually specify EdgeOne Zone ID (skips auto-discovery)
# dns_edgeone_zone_id = zone-2noz78a8ev6k- Secure the credentials file:
chmod 600 ~/.secrets/certbot/edgeone.iniRun certbot certonly with the dns-edgeone authenticator:
certbot certonly \
-a dns-edgeone \
--dns-edgeone-credentials ~/.secrets/certbot/edgeone.ini \
--dns-edgeone-propagation-seconds 30 \
-d example.com \
-d "*.example.com"Certbot renews certificates automatically before they expire (usually within 30 days) via cron or a systemd timer.
Test renewal using dry-run mode:
certbot renew --dry-run| Argument | Default | Description |
|---|---|---|
--dns-edgeone-credentials |
Required | Path to INI credentials file containing EdgeOne API secret_id and secret_key |
--dns-edgeone-propagation-seconds |
30 |
Seconds to wait for DNS propagation before ACME validation |
--dns-edgeone-zone-id |
Auto | Optional EdgeOne Zone ID (e.g. zone-xxxxxx) to override automatic discovery |
Run the test suite using pytest:
uv pip install pytest
pytest -v