Hi Microsoft Community,
we are facing a persistent issue when trying to bind a custom domain to the Gateway endpoint of an Azure API Management instance.
Environment:
- Azure API Management SKU: Consumption
- Region: West Europe
- Endpoint type: Gateway / Proxy
- Certificate source: Azure Key Vault secret containing PFX
- Certificate type: App Service Certificate / GoDaddy-issued certificate
- Certificate algorithm: SHA256RSA, 2048-bit
- Certificate validity: valid until December 2026
- APIM identity: System-assigned managed identity
- Network: No VNet integration
- Key Vault public network access: enabled
Problem:
Binding the custom domain to the APIM Gateway consistently fails with:
Code:
UpdateApiServiceFailed
Message:
"Service update has failed. Please find the details in the notification."
This happens both:
- via Terraform using azurerm_api_management_custom_domain
- manually through the Azure Portal
When configured manually in the Azure Portal, the custom domain initially appears, but after a few minutes it silently disappears again. The Portal UI does not show a detailed error message.
We have a very similar setup in another Azure subscription / tenant using the same Terraform code, the same APIM SKU, the same certificate issuer, and the same general Key Vault-based certificate approach. That environment works without issues.
What we already verified:
Certificate:
- CN matches the custom domain
- SAN entries are correct
- Private key is present
- Full certificate chain is included
- Certificate is valid
- SHA256RSA, 2048-bit key
- PFX structure was compared with the working environment and appears equivalent
- Issuer is the same as in the working environment
Key Vault:
- Secret exists and is enabled
- Secret reference used by APIM is versionless
- Secret content type is application/x-pkcs12
- APIM managed identity has Get and List permissions on secrets and certificates
- Deployment service principal has the required Key Vault permissions
- Public network access is enabled
- Terraform can successfully read the Key Vault secret
APIM:
- provisioningState is Succeeded before each attempt
- No VNet integration
- Consumption SKU
- System-assigned managed identity is enabled
DNS:
- CNAME points to the APIM default gateway hostname
- Required asuid TXT validation record exists
- DNS validation appears to be correct
Terraform / deployment observations:
- Key Vault secret GET succeeds
- There is a 403 on CertificateContactsGet in the Terraform logs, but Terraform explicitly logs this as tolerated because of the legacy plugin SDK
- The fatal error happens later during the APIM custom domain provisioning step
Impact:
We cannot complete the custom domain binding for the APIM Gateway endpoint. The same configuration works in another subscription / tenant, so this appears to be either an internal APIM provisioning issue or a subscription/resource-specific issue.
Thanks in advance.