Akamai CPS DV Certificate
Automated Domain Validated TLS enrollment with DNS/HTTP challenge outputs wired for Edge DNS.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan: findings disclosed (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o akamai-cps-dv-certificate-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/akamai-cps-dv-certificate/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle akamai-cps-dv-certificate-1.0.0.sigstore.json \
akamai-cps-dv-certificate-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "19e4ec9ec2ae6fb54cf9ac27d520a40a103ed50f82235bf39bcf3bd312cd832c akamai-cps-dv-certificate-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "cps_dv_certificate" {
source = "www.iac-bazaar.com/iac-bazaar/akamai-cps-dv-certificate/akamai"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads static-verified because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/akamai-cps-dv-certificate?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, static-verified on IaC Bazaar: [Akamai CPS DV Certificate](https://www.iac-bazaar.com/catalog/akamai-cps-dv-certificate?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "cps_dv_certificate" {
source = "www.iac-bazaar.com/iac-bazaar/akamai-cps-dv-certificate/akamai"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
akamai-cps-dv-certificate
Automated Domain Validated (Let's Encrypt) TLS enrollment in Akamai CPS, with
ACME DNS-01 challenge records wired straight into Edge DNS and validation
polling. Works with Terraform and OpenTofu (>= 1.6), Akamai provider
>= 10.0, < 11.0.
Secure defaults:
- Enhanced TLS network, SNI-only, SHA-256
- TLS 1.0/1.1 disallowed, OCSP stapling on
- Challenge TXT records can be published into your Edge DNS zone (opt-in, see
the two-phase bootstrap below);
dns_challenges/http_challengesare also exported for external DNS
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
Related modules
huawei-tls-certificate
A public TLS certificate bought through Huawei CCM, and its application. Applying is a purchase, so brand, type and validity have no defaults and every combination rule is checked at plan. It does not renew itself. The provider accepts Huawei's privacy terms on every application, so the module waits for a person to. Validation records appear one refresh after the first apply.
alicloud-ssl-certificate
A certificate uploaded into Certificate Management Service for SLB, ALB, CDN and API Gateway to reference. The private key is an argument, so it lands in the Terraform state and the README says so plainly. SM2 is a signing pair plus an encryption pair and the module refuses a half-filled set, which would upload something no client can handshake with.
azure-managed-certificate
A free App Service managed certificate for a custom subdomain, with its hostname binding, the SNI binding that puts it to use, and optionally the DNS records. Microsoft blocks issuance and renewal when the CNAME passes through anything before the app, so the module writes the direct record and refuses the wildcards, apex names and long hostnames the product does not support.
tencent-ssl-certificate
A free domain-validated certificate from Tencent Cloud SSL. DNS_AUTO writes the record for you and silently only works when the domain is on DNSPod, so the module refuses it unless you confirm that. The issued private key is a computed attribute and therefore in state, and the resource finishes before the certificate is issued, so read the status output.
ibm-public-certificate
A publicly-trusted certificate issued into Secrets Manager, validated over DNS through Cloud Internet Services, with both configurations created here rather than left to a console. Staging issues a certificate no browser trusts while looking like success, so it is refused by name; auto-rotation and key rotation are on, because a ninety-day certificate nothing renews is a dated outage.
aws-acm
Requests a public, DNS-validated ACM TLS certificate that ACM auto-renews forever, outputting the validation records to publish - CT logging on, wildcards and SANs supported.