AkamaiStatic-verified

Akamai CPS DV Certificate

Automated Domain Validated TLS enrollment with DNS/HTTP challenge outputs wired for Edge DNS.

terraformEdge & DNSakamai

Compare Managed TLS Certificates across clouds →

akamai-cps-dv-certificatevizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan: findings disclosed (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-06-28 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o akamai-cps-dv-certificate-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/akamai-cps-dv-certificate/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle akamai-cps-dv-certificate-1.0.0.sigstore.json \
  akamai-cps-dv-certificate-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "19e4ec9ec2ae6fb54cf9ac27d520a40a103ed50f82235bf39bcf3bd312cd832c  akamai-cps-dv-certificate-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "cps_dv_certificate" {
  source  = "www.iac-bazaar.com/iac-bazaar/akamai-cps-dv-certificate/akamai"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads static-verified because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: static-verified](https://www.iac-bazaar.com/api/artifacts/akamai-cps-dv-certificate/badge)](https://www.iac-bazaar.com/catalog/akamai-cps-dv-certificate?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, static-verified on IaC Bazaar: [Akamai CPS DV Certificate](https://www.iac-bazaar.com/catalog/akamai-cps-dv-certificate?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "cps_dv_certificate" {
  source  = "www.iac-bazaar.com/iac-bazaar/akamai-cps-dv-certificate/akamai"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: static-verified

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

akamai-cps-dv-certificate

Automated Domain Validated (Let's Encrypt) TLS enrollment in Akamai CPS, with ACME DNS-01 challenge records wired straight into Edge DNS and validation polling. Works with Terraform and OpenTofu (>= 1.6), Akamai provider >= 10.0, < 11.0.

Secure defaults:

  • Enhanced TLS network, SNI-only, SHA-256
  • TLS 1.0/1.1 disallowed, OCSP stapling on
  • Challenge TXT records can be published into your Edge DNS zone (opt-in, see the two-phase bootstrap below); dns_challenges/http_challenges are also exported for external DNS

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs

Related modules

Static validatedLive test pending

huawei-tls-certificate

A public TLS certificate bought through Huawei CCM, and its application. Applying is a purchase, so brand, type and validity have no defaults and every combination rule is checked at plan. It does not renew itself. The provider accepts Huawei's privacy terms on every application, so the module waits for a person to. Validation records appear one refresh after the first apply.

View module
Static validatedLive test pending

alicloud-ssl-certificate

A certificate uploaded into Certificate Management Service for SLB, ALB, CDN and API Gateway to reference. The private key is an argument, so it lands in the Terraform state and the README says so plainly. SM2 is a signing pair plus an encryption pair and the module refuses a half-filled set, which would upload something no client can handshake with.

View module
Static validatedLive test pending

azure-managed-certificate

A free App Service managed certificate for a custom subdomain, with its hostname binding, the SNI binding that puts it to use, and optionally the DNS records. Microsoft blocks issuance and renewal when the CNAME passes through anything before the app, so the module writes the direct record and refuses the wildcards, apex names and long hostnames the product does not support.

View module
Static validatedLive test pending

tencent-ssl-certificate

A free domain-validated certificate from Tencent Cloud SSL. DNS_AUTO writes the record for you and silently only works when the domain is on DNSPod, so the module refuses it unless you confirm that. The issued private key is a computed attribute and therefore in state, and the resource finishes before the certificate is issued, so read the status output.

View module
Static validatedLive test pending

ibm-public-certificate

A publicly-trusted certificate issued into Secrets Manager, validated over DNS through Cloud Internet Services, with both configurations created here rather than left to a console. Staging issues a certificate no browser trusts while looking like success, so it is refused by name; auto-rotation and key rotation are on, because a ninety-day certificate nothing renews is a dated outage.

View module
Live-tested

aws-acm

Requests a public, DNS-validated ACM TLS certificate that ACM auto-renews forever, outputting the validation records to publish - CT logging on, wildcards and SANs supported.

View module