Tutorial Tutorial Tutorial Application Services Application Services Application Services ~24 phút ~24 min ~24 នាទី Đồng bộ 2026-06-10 Synced 2026-06-10 ធ្វើសមកាល 2026-06-10

Cài đặt HTTPS Configure HTTPS settings ទាញយក HTTPS

Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។

← Danh mục ← Catalog ← បញ្ជី

Giải thích nhanh Quick context បរិបទរហ័ស

Thuộc nhóm Application Services — tập trung bảo vệ, tăng tốc và vận hành ứng dụng/web phía trước origin. Tutorial «3 – Configure HTTPS settings» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Docs gốc chia khoảng 3 bước chính; bản tóm tắt dưới đây giúp bạn nắm khung trước khi làm theo từng lệnh.

This tutorial shows how to enable TLS 1.3, Automatic HTTPS Rewrites, and Strict SSL mode using the updated v5 provider.

វគ្គបណ្តុះបណ្តាលនេះបង្ហាញពីរបៀបដើម្បីអនុញ្ញាត TLS 1.3, Automatic HTTPS Rewrites និងរបៀប SSL ដោយប្រើអ្នកផ្គត់ផ្គង់ v5 បានបច្ចុប្បន្ន។

Lưu ý Note ចំណាំ

Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម

  • Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
  • Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
  • Kiểm tra token/API và state backend trước khi chạy trên môi trường production.
  • Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
  • This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
  • Open the Official docs link below for CLI commands, code snippets, and full screenshots.
  • Verify API tokens and the state backend before running against production.
  • Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
  • នេះគឺជាការបញ្ជាក់អំពី Orange Cloud Learning Hub — វាគឺជាការផ្លាស់ប្តូរនៃឯកសារផ្លូវការ។
  • ចុចតំណភ្ជាប់ Docs Official នៅខាងក្រោមសម្រាប់ការបញ្ជា CLI, សៀវភៅកូដនិងរូបថតពេញលេញ។
  • សូមពិនិត្យមើល API tokens និងការបង្វិលប្រព័ន្ធប្រតិបត្តិការមុនពេលធ្វើការប្រឆាំងនឹងការផលិត។
  • Cloudflare បានផ្លាស់ប្តូរជាធម្មតានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅ។

Overview Overview Overview

Phần «Tổng quan» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Overview» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Sau khi thiết lập các bản ghi cơ bản DNS, bạn có thể cấu hình cài đặt khu vực bằng cách sử dụng Terraform. Hướng dẫn này cho thấy cách kích hoạt TLS 1.3, Automatic HTTPS Rewrites và Strict SSL mode bằng cách sử dụng nhà cung cấp v5 được cập nhật.
After setting up basic DNS records, you can configure zone settings using Terraform. This tutorial shows how to enable TLS 1.3, Automatic HTTPS Rewrites, and Strict SSL mode using the updated v5 provider.
បន្ទាប់ពីកំណត់កំណត់ DNS ដំបូងអ្នកអាចកំណត់កំណត់កំណត់តំបន់ដោយប្រើ Terraform ។ វគ្គបណ្តុះបណ្តាលនេះបង្ហាញពីរបៀបដើម្បីអនុញ្ញាត TLS 1.3, Automatic HTTPS Rewrites និង Strict SSL mode ដោយប្រើអ្នកផ្គត់ផ្គង់ v5 បានបច្ចុប្បន្ន។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Điều kiện Prerequisites គោលបំណង

Phần «Yêu cầu trước» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Prerequisites" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «គោលបំណង» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
  • Hướng dẫn hoàn thành 1 và 2
  • Chứng chỉ SSL hợp lệ trên máy chủ gốc của bạn (sử dụng Cloudflare Origin CA để tạo một chứng chỉ cho chế độ SSL nghiêm ngặt)
  • Completed tutorials 1 and 2
  • Valid SSL certificate on your origin server (use the Cloudflare Origin CA to generate one for strict SSL mode)
  • វគ្គបណ្តុះបណ្តាលពេញលេញ 1 និង 2
  • វិញ្ញាបនប័ត្រ SSL ដែលមានប្រសិទ្ធិភាពនៅលើបណ្តាញដើមរបស់អ្នក (ប្រើសម្រាប់ Cloudflare Origin CA ដើម្បីបង្កើតវិញ្ញាបនប័ត្រមួយសម្រាប់ប្រព័ន្ធ SSL)
Các đoạn mã Terraform dưới đây chỉ đề cập đến v5 SDK.
Terraform code snippets below refer to the v5 SDK only.
Terraform សៀវភៅកូដខាងក្រោមបង្ហាញតែសម្រាប់ SDK v5 ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

1.Điều Tạo Configuration Zone Setup 1. Create zone setting configuration 1 ។ ការបង្កើតកំណត់កំណត់កំណត់កំណត់តំបន់

Tạo new branch and add zone settings:

Read the "1. Create zone setting configuration" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «1 ។ ការបង្កើតកំណត់កំណត់កំណត់កំណត់តំបន់» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Tạo một chi nhánh mới và thêm cài đặt khu vực:
Create a new branch and add zone settings:
បានបង្កើតកញ្ចប់ថ្មីនិងបន្ថែមកំណត់តំបន់:
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
git checkout -b step3-zone-settings
Thêm những điều sau đây vào tệp main.tf của bạn:
Add the following to your main.tf file:
បន្ថែមបញ្ជីខាងក្រោមទៅឯកសារ main.tf របស់អ្នក:
text
# Enable TLS 1.3

resource "cloudflare_zone_setting" "tls_1_3" {

  zone_id    = var.zone_id

  setting_id = "tls_1_3"

  value      = "on"

}


# Enable automatic HTTPS rewrites

resource "cloudflare_zone_setting" "automatic_https_rewrites" {

  zone_id    = var.zone_id

  setting_id = "automatic_https_rewrites"

  value      = "on"

}


# Set SSL mode to strict

resource "cloudflare_zone_setting" "ssl" {

  zone_id    = var.zone_id

  setting_id = "ssl"

  value      = "strict"

}

2.Đối với Dự đoán và áp dụng các thay đổi 2. Preview and apply the changes 2 ។ ពិនិត្យឡើងវិញនិងអនុវត្តការផ្លាស់ប្តូរ

Phần «Preview và apply changes» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "2. Preview and apply the changes" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «2 ។ ពិនិត្យឡើងវិញនិងអនុវត្តការផ្លាស់ប្តូរ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Xem xét các thay đổi được đề xuất:
Review the proposed changes:
សូមពិនិត្យមើលការផ្លាស់ប្តូរដែលបានផ្តល់ជូន:
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
terraform plan
Sản lượng dự kiến
Expected output
ផលិតផលដែលគួរឱ្យចាប់អារម្មណ៍
text
Plan: 3 to add, 0 to change, 0 to destroy.


Terraform will perform the following actions:


  # cloudflare_zone_setting.automatic_https_rewrites will be created

  + resource "cloudflare_zone_setting" "automatic_https_rewrites" {

      + setting_id = "automatic_https_rewrites"

      + value      = "on"

      + zone_id    = "your-zone-id"

    }


  # cloudflare_zone_setting.ssl will be created

  + resource "cloudflare_zone_setting" "ssl" {

      + setting_id = "ssl"

      + value      = "strict"

      + zone_id    = "your-zone-id"

    }


  # cloudflare_zone_setting.tls_1_3 will be created

  + resource "cloudflare_zone_setting" "tls_1_3" {

      + setting_id = "tls_1_3"

      + value      = "on"

      + zone_id    = "your-zone-id"

    }
Cam kết và kết hợp các thay đổi:
Commit and merge the changes:
ការផ្លាស់ប្តូរនិងការផ្លាស់ប្តូរ:
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
git add main.tf

git commit -m "Step 3 - Enable TLS 1.3, automatic HTTPS rewrites, and strict SSL"

git checkout main

git merge step3-zone-settings

git push
Trước khi áp dụng các thay đổi, hãy thử kết nối với TLS 1.3\. Về mặt kỹ thuật, bạn không nên có thể với cài đặt mặc định. Để làm theo bài kiểm tra này, bạn sẽ cần compile curl against BoringSSL ↗.
Before applying the changes, try to connect with TLS 1.3\. Technically, you should not be able to with default settings. To follow along with this test, you will need to compile curl against BoringSSL ↗.
មុនពេលអនុវត្តការផ្លាស់ប្តូរធ្វើឱ្យប្រាកដជាមួយ TLS 1.3\ ។ បច្ចេកទេស, អ្នកគួរតែមិនអាចជាមួយនឹងការកំណត់ទូទៅ. ដើម្បីធ្វើតេស្តនេះអ្នកនឹងត្រូវការ compile curl against BoringSSL ↗ ។
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
curl -v --tlsv1.3 https://www.example.com 2>&1 | grep "SSL connection\|error"
Như đã hiển thị ở trên, bạn nên nhận được lỗi vì TLS 1.3 chưa được bật trong khu vực của bạn. Hãy kích hoạt nó bằng cách chạy terraform apply và thử lại.
As shown above, you should receive an error because TLS 1.3 is not yet enabled on your zone. Enable it by running terraform apply and try again.
ដូចដែលបានបង្ហាញនៅលើនេះអ្នកគួរតែទទួលបានបញ្ហានេះដោយសារតែ TLS 1.3 មិនត្រូវបានអនុញ្ញាតនៅក្នុងតំបន់របស់អ្នកទេ។ សូមអនុញ្ញាតឱ្យវាដោយធ្វើដំណើរ terraform apply និងធ្វើដំណើរបន្ទាប់មក។
Sử dụng cấu hình:
Apply the configuration:
ទាញយក Configuration:
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
terraform apply
Nhấn yes khi được nhắc.
Type yes when prompted.
ទាញយក yes នៅពេលដែលអ្នកកំពុងទាញយក

3 Cái Kiểm tra cài đặt 3. Verify the settings 3 ។ សូមពិនិត្យមើលកំណត់

Phần «Xác minh settings» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "3. Verify the settings" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «3 ។ សូមពិនិត្យមើលកំណត់» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Hãy thử lệnh tương tự như trước. Lệnh bây giờ sẽ thành công.
Try the same command as before. The command will now succeed.
សូមធ្វើការគ្រប់គ្រងដូចមុន។ ការគ្រប់គ្រងនេះនឹងជោគជ័យ។
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
curl -v --tlsv1.3 https://www.example.com 2>&1 | grep "SSL connection\|error"
json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"/directory/","name":"Directory"}},{"@type":"ListItem","position":2,"item":{"@id":"/terraform/","name":"Terraform"}},{"@type":"ListItem","position":3,"item":{"@id":"/terraform/tutorial/","name":"Tutorials"}},{"@type":"ListItem","position":4,"item":{"@id":"/terraform/tutorial/configure-https-settings/","name":"3 – Configure HTTPS settings"}}]}

Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។

Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗