# Certificates resources

[View in Terraform Registry](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/digital_certificate)

A digital certificate is the SSL/TLS certificate and private key pair that lets an application answer over HTTPS. The Azion Terraform Provider manages the certificates of [Certificate Manager](/en/documentation/platform/workloads/certificate-manager/certificates/) with one resource and reads them with two data sources.

---

## Certificate resources

| Resource                                                                                                                         | Description                                |
| -------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------ |
| [`azion_digital_certificate`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/digital_certificate) | Creates and manages a digital certificate. |

`azion_digital_certificate` requires three string arguments: `name`, the name of the certificate; `certificate`, the SSL/TLS certificate in PEM format; and `private_key`, the private key in PEM format. It exports `id`, a string that holds the unique ID of the certificate. The Terraform Registry page of the resource lists every argument.

---

## Data sources

| Data source                                                                                                                           | Description                    |
| ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------ |
| [`azion_digital_certificates`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/digital_certificates) | Lists digital certificates.    |
| [`azion_digital_certificate`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/digital_certificate)   | Reads one digital certificate. |

---

## Example

This configuration pins the provider, creates a certificate from a certificate file and a private key file in the `certificates` folder of the module, reads the existing certificates, and outputs the ID of the certificate. It reads your personal token from the `api_token` variable that the [Azion Terraform Provider quickstart](/en/documentation/devtools/terraform/getting-started/) declares.

```hcl
terraform {
  required_providers {
    azion = {
      source  = "aziontech/azion"
      version = "2.0.0"
    }
  }
}

provider "azion" {
  api_token = var.api_token
}

# Create digital certificate
resource "azion_digital_certificate" "my_cert" {
  name        = "certificate-mydomain"
  certificate = file("${path.module}/certificates/mydomain.pem")
  private_key = file("${path.module}/certificates/mydomain-key.pem")
}

# Query existing certificates
data "azion_digital_certificates" "all" {}

output "certificate_id" {
  value = azion_digital_certificate.my_cert.id
}
```

To keep the certificate and the private key out of the configuration code, declare them as sensitive variables. This block replaces the `azion_digital_certificate` resource of the configuration above:

```hcl
variable "ssl_certificate" {
  type        = string
  description = "SSL certificate in PEM format"
  sensitive   = true
}

variable "ssl_private_key" {
  type        = string
  description = "SSL private key in PEM format"
  sensitive   = true
}

resource "azion_digital_certificate" "my_cert" {
  name        = "my-certificate"
  certificate = var.ssl_certificate
  private_key = var.ssl_private_key
}
```

A shorter form, with `cert.pem` and `key.pem` at the root of the module, is on [Resources and data sources](/en/documentation/devtools/terraform/examples/).

---

## Related resources

- [Applications resources](/en/documentation/devtools/terraform/applications.md): The resources that manage applications, their cache settings, rules, device groups, and function instances.
- [Edge DNS resources](/en/documentation/devtools/terraform/dns.md): The resources that manage DNS zones, their records, and their DNSSEC settings.
- [Security resources](/en/documentation/devtools/terraform/security.md): The resources that manage firewalls, WAF rule sets, and network lists.
- [Migrate from provider v1.x to v2.0](/en/documentation/devtools/terraform/terraform-migration-v3-to-v4.md): The changes to make when a configuration still uses provider v1.x and API v3.
