๐Ÿ”’ Netlify SSL ์ธ์ฆ์„œ ์ž๋™ ๊ฐฑ์‹  ์˜ค๋ฅ˜ ํ•ด๊ฒฐ ๊ธฐ๋ก (Route 53 ๊ด€๋ฆฌ ๋ฐฉ์‹)

Netlify์— ๋ฐฐํฌํ•œ ์„œ๋น„์Šค์—์„œ SSL ์ธ์ฆ์„œ ์ž๋™ ๊ฐฑ์‹ ์ด ์ •์ƒ์ ์œผ๋กœ ์ด๋ค„์ง€์ง€ ์•Š๋Š” ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ–ˆ๋‹ค.
DNS๋Š” AWS Route 53์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์—ˆ๊ณ , ๊ฐ‘์ž‘์Šค๋Ÿฝ๊ฒŒ ๋‚˜ํƒ€๋‚œ ์˜ค๋ฅ˜๋ผ ์›์ธ์„ ํŒŒ์•…ํ•˜๋Š” ๋ฐ ์‹œ๊ฐ„์ด ํ•„์š”ํ–ˆ๋‹ค.
์‚ฌ์‹ค ์ด์ „๋ถ€ํ„ฐ โ€œ์„ค์ •์ด ๋ญ”๊ฐ€ ์ œ๋Œ€๋กœ ์•ˆ ๋œ ๊ฒƒ ๊ฐ™์€๋ฐโ€ฆ ๊ทธ๋ž˜๋„ ์ž˜ ์—ฐ๊ฒฐ๋˜๋„ค?โ€๋ผ๋Š” ์˜์‹ฌ์ด ๋“ค๊ธด ํ–ˆ์ง€๋งŒ, ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•˜๊ธฐ ์ „๊นŒ์ง€๋Š” ๋Œ€์ˆ˜๋กญ์ง€ ์•Š๊ฒŒ ๋„˜๊ฒผ๋‹ค.
ํ•˜์ง€๋งŒ ๊ฒฐ๊ตญ ๋ฌธ์ œ๊ฐ€ ํ„ฐ์ง€๋ฉด์„œ โ€œ์˜ฌ ๊ฒŒ ์™”๊ตฌ๋‚˜โ€ฆโ€ ์‹ถ์—ˆ๊ณ , ์ด์— ๋ฌธ์ œ๋ฅผ ๋ถ„์„ํ•˜๊ณ  ํ•ด๊ฒฐํ•˜๊ธฐ๊นŒ์ง€์˜ ๊ณผ์ •์„ ์•„๋ž˜์™€ ๊ฐ™์ด ์ •๋ฆฌํ–ˆ๋‹ค.

๐ŸŒ ๊ธฐ๋ณธ ๊ตฌ์„ฑ

  • DNS ๊ด€๋ฆฌ: AWS Route 53
  • ํ˜ธ์ŠคํŒ…: Netlify
  • SSL ์ธ์ฆ์„œ: Let's Encrypt (Netlify ์ž๋™ ๋ฐœ๊ธ‰ ๋ฐ ๊ฐฑ์‹ )
Route 53์„ ์œ ์ง€ํ•˜๋ฉด์„œ Netlify์˜ Letโ€™s Encrypt ์ž๋™ SSL ๊ธฐ๋Šฅ์„ ํ•จ๊ป˜ ์‚ฌ์šฉํ•˜๋Š” ๊ตฌ์„ฑ์ด๋‹ค.

โš™๏ธ DNS ์„ค์ • (Route 53)

โœ… ๋ฃจํŠธ ๋„๋ฉ”์ธ (A ๋ ˆ์ฝ”๋“œ)
์ด ๋‘ IP๋Š” Netlify ๊ณต์‹ ๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ ์ฃผ์†Œ๋‹ค.
์™ธ๋ถ€ DNS๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ๋Š” ๋‘ ๊ฐœ ๋ชจ๋‘ ๋“ฑ๋กํ•ด์•ผ ํ•œ๋‹ค.
๐Ÿ“˜ ๊ณต์‹ ๋ฌธ์„œ: Netlify Docs โ€” Configure external DNS
โœ… ์„œ๋ธŒ๋„๋ฉ”์ธ (CNAME)
โš ๏ธ https:// ํ˜น์€ / ๊ฐ™์€ ๊ฒฝ๋กœ๋ฅผ ํฌํ•จํ•˜๋ฉด ์•ˆ๋œ๋‹ค.
๋„๋ฉ”์ธ ์ด๋ฆ„๋งŒ ์ž…๋ ฅํ•ด์•ผ Netlify์˜ DNS ๊ฒ€์ฆ์ด ์ •์ƒ์ ์œผ๋กœ ํ†ต๊ณผ๋œ๋‹ค.
โœ… ๋„ค์ž„์„œ๋ฒ„ (NS)
Route 53์˜ ๊ธฐ๋ณธ ๋„ค์ž„์„œ๋ฒ„๋ฅผ ๊ทธ๋Œ€๋กœ ์œ ์ง€ํ•œ๋‹ค.
Netlify DNS๋ฅผ ๋™์‹œ์— ํ™œ์„ฑํ™”ํ•˜๋ฉด ์ถฉ๋Œ์ด ๋ฐœ์ƒํ•˜๋ฏ€๋กœ,
๋ฐ˜๋“œ์‹œ Netlify DNS๋Š” ๋น„ํ™œ์„ฑํ™” ์ƒํƒœ๋กœ ์œ ์ง€ํ•ด์•ผ ํ•œ๋‹ค.

๐Ÿงฉ Netlify ์„ค์ •

Domain Management

  • ๋‘ ํ•ญ๋ชฉ ๋ชจ๋‘ "Verified" ์ƒํƒœ์—ฌ์•ผ ์ •์ƒ์ด๋‹ค.

HTTPS (SSL/TLS)

  • ์ธ์ฆ์„œ: Letโ€™s Encrypt
  • โ€œRenew certificateโ€ ํด๋ฆญ ์‹œ ์ž๋™ ๋ฐœ๊ธ‰
  • ์ดํ›„ 90์ผ ์ฃผ๊ธฐ๋กœ ์ž๋™ ๊ฐฑ์‹ ๋˜๋ฉฐ, ๋ณ„๋„์˜ ์ˆ˜๋™ ๊ด€๋ฆฌ๊ฐ€ ํ•„์š” ์—†๋‹ค.

๐Ÿšง ๋ฌธ์ œ ํ•ด๊ฒฐ ๊ธฐ๋ก

  1. CNAME์— https:// ํฌํ•จ โ†’ DNS ๊ฒ€์ฆ ์‹คํŒจ
    1. โ†’ ๊ฐ’ ์ˆ˜์ • ํ›„ ์ฆ‰์‹œ โ€œPending DNS verificationโ€ ๋ฌธ์ œ ํ•ด๊ฒฐ
  1. NXDOMAIN looking up TXT for _acme-challenge ๋ฐœ์ƒ
    1. โ†’ ์™€์ผ๋“œ์นด๋“œ(*.) ์ธ์ฆ ์‹œ๋„ ์‹คํŒจ โ†’ ์™€์ผ๋“œ์นด๋“œ ํ•ญ๋ชฉ ์‚ญ์ œ ํ›„ ์žฌ๋ฐœ๊ธ‰ ์„ฑ๊ณต
  1. doesnโ€™t appear to be served by Netlify ๊ฒฝ๊ณ 
    1. โ†’ A ๋ ˆ์ฝ”๋“œ๊ฐ€ ์ž˜๋ชป๋œ IP๋ฅผ ๊ฐ€๋ฆฌํ‚ด โ†’ Netlify ๊ณต์‹ IP๋กœ ์ˆ˜์ •
  1. Netlify DNS propagating... ํ‘œ์‹œ ์ง€์†
    1. โ†’ Netlify DNS์™€ Route 53 DNS๊ฐ€ ๋™์‹œ์— ํ™œ์„ฑํ™” โ†’ Netlify DNS ์˜์—ญ ์‚ญ์ œ ํ›„ ์ •์ƒํ™”

๐Ÿ” ๊ฒ€์ฆ ๋ฐฉ๋ฒ•

โœ…ย DNS ํ™•์ธ
๊ฒฐ๊ณผ์— 75.2.60.5, 99.83.229.126, name.netlify.app๊ฐ€ ํ‘œ์‹œ๋˜๋ฉด ์ •์ƒ์ด๋‹ค.
โœ…ย SSL ํ™•์ธ
์ •์ƒ ์‘๋‹ต ์˜ˆ์‹œ:
๋ธŒ๋ผ์šฐ์ €์—์„œ ํ™•์ธ
  • https://seoulmoment.com.tw ๋˜๋Š” https://www.seoulmoment.com.tw ์ ‘์†
  • ์ฃผ์†Œ์ฐฝ ์™ผ์ชฝ ๐Ÿ”’ ์ž๋ฌผ์‡  ์•„์ด์ฝ˜ ํด๋ฆญ
  • โ€œ์ธ์ฆ์„œ(Certificate)โ€ ์ •๋ณด์—์„œ
    • ๋ฐœ๊ธ‰ ๊ธฐ๊ด€: Letโ€™s Encrypt
    • ์œ ํšจ ๊ธฐ๊ฐ„: 90์ผ ๋‹จ์œ„ ์ž๋™ ๊ฐฑ์‹ 
    • โ€œ์œ ํšจํ•จ(Valid)โ€ ์ƒํƒœ๋กœ ํ‘œ์‹œ๋˜๋Š”์ง€ ํ™•์ธ
์ถ”๊ฐ€ ์ ๊ฒ€
SSL Labs ์—์„œ ๋„๋ฉ”์ธ(seoulmoment.com.tw)์„ ์ž…๋ ฅํ•˜์—ฌ ์ธ์ฆ์„œ ์œ ํšจ์„ฑ๊ณผ SSL ๋“ฑ๊ธ‰(A~F)์„ ํ™•์ธ

๐Ÿย ์ตœ์ข… ์ƒํƒœ

  • DNS๋Š” AWS Route 53์—์„œ ๊ด€๋ฆฌ
  • Netlify๋Š” ์™ธ๋ถ€ DNS๋ฅผ ํ†ตํ•ด HTTPS ์ธ์ฆ ํ™œ์„ฑํ™”
  • SSL์€ Letโ€™s Encrypt ์ž๋™ ๋ฐœ๊ธ‰ ๋ฐ ๊ฐฑ์‹ 
  • HTTP ์š”์ฒญ์€ ์ž๋™์œผ๋กœ HTTPS๋กœ ๋ฆฌ๋””๋ ‰์…˜
  • https://seoulmoment.com.tw, https://www.seoulmoment.com.tw ๋ชจ๋‘ ์ •์ƒ ์ ‘์† ๊ฐ€๋Šฅ
โœ… Route 53์„ ์œ ์ง€ํ•˜๋ฉด์„œ Netlify์˜ ์ž๋™ SSL ๋ฐœ๊ธ‰ ๊ธฐ๋Šฅ์„ ์™„๋ฒฝํžˆ ๋™์ž‘ํ•˜๋„๋ก ๊ตฌ์„ฑ ์™„๋ฃŒ.

๐Ÿงญ Troubleshooting ์ฒดํฌ๋ฆฌ์ŠคํŠธ

๋ฌธ์ œ ์ฆ์ƒ
์ฃผ์š” ์›์ธ
ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•
doesnโ€™t appear to be served by Netlify
A ๋ ˆ์ฝ”๋“œ๊ฐ€ ์ž˜๋ชป๋œ IP๋ฅผ ๊ฐ€๋ฆฌํ‚ค๊ฑฐ๋‚˜, DNS ์บ์‹œ ๋ฏธ๊ฐฑ์‹ 
Route 53 A ๋ ˆ์ฝ”๋“œ๋ฅผ 75.2.60.5, 99.83.229.126์œผ๋กœ ์ˆ˜์ • ํ›„ 10~30๋ถ„ ๋Œ€๊ธฐ
Pending DNS verification
CNAME ๊ฐ’์— https:// ํฌํ•จ ๋˜๋Š” DNS ์ „ํŒŒ ์ง€์—ฐ
CNAME ๊ฐ’์„ seoul-moment.netlify.app๋กœ ์ˆ˜์ • (https ์ œ๊ฑฐ) โ†’ ์ „ํŒŒ ํ›„ โ€œRenew certificateโ€ ํด๋ฆญ
NXDOMAIN looking up TXT for _acme-challenge
์™€์ผ๋“œ์นด๋“œ(*.) ์ธ์ฆ ์‹œ๋„ ์‹œ TXT ๊ฒ€์ฆ ์‹คํŒจ
Netlify Dashboard์—์„œ *.๋„๋ฉ”์ธ ์‚ญ์ œ ํ›„ ๋ฃจํŠธ/WWW๋งŒ ๋‚จ๊ธฐ๊ณ  ์žฌ๋ฐœ๊ธ‰
Netlify DNS propagating...
Netlify DNS์™€ Route 53 DNS ์ค‘๋ณต ํ™œ์„ฑํ™”
Netlify์˜ DNS zone ์‚ญ์ œ (Route 53๋งŒ ์œ ์ง€)
SSL ๊ฐฑ์‹  ์‹คํŒจ (๋งŒ๋ฃŒ ๊ฒฝ๊ณ )
DNS ์ „ํŒŒ ์‹œ์ ์— ์ž ์‹œ Netlify ์—ฐ๊ฒฐ์ด ๋Š๊น€
DNS ํ™•์ธ ํ›„ โ€œRenew certificateโ€ ํด๋ฆญ ๋˜๋Š” ํ•˜๋ฃจ ๋‚ด ์ž๋™ ๋ณต๊ตฌ๋จ
HTTP๋กœ ์ ‘์† ์‹œ ๋ณด์•ˆ ๊ฒฝ๊ณ 
SSL ๋ฐœ๊ธ‰์€ ์™„๋ฃŒ๋์œผ๋‚˜ HTTPS ๋ฆฌ๋””๋ ‰์…˜ ๋ฏธ์ ์šฉ
Netlify โ€œForce HTTPSโ€ ์˜ต์…˜ ํ™œ์„ฑํ™” (Site Settings โ†’ Domain management โ†’ HTTPS)

๐Ÿ”„ ์ ๊ฒ€ ์ˆœ์„œ (Quick Flow)

  1. DNS ํ™•์ธ โ†’ dig seoulmoment.com.tw, dig www.seoulmoment.com.tw
  1. ๋„๋ฉ”์ธ ๊ฒ€์ฆ ์ƒํƒœ ํ™•์ธ โ†’ Netlify Dashboard โ†’ Domain management
  1. Netlify DNS ๋น„ํ™œ์„ฑํ™” ์—ฌ๋ถ€ ํ™•์ธ โ†’ Netlify DNS zone ์‚ญ์ œ (Route 53๋งŒ ์œ ์ง€)
  1. SSL ์žฌ๋ฐœ๊ธ‰ ์‹œ๋„ โ†’ โ€œRenew certificateโ€ ํด๋ฆญ
  1. HTTPS ํ…Œ์ŠคํŠธ โ†’ curl -I https://seoulmoment.com.tw ๊ฒฐ๊ณผ ํ™•์ธ (server: Netlify)

๐Ÿ’ก ์ถ”๊ฐ€ ํŒ

  • DNS ์ „ํŒŒ๋Š” ์ตœ๋Œ€ 30๋ถ„~1์‹œ๊ฐ„ ๊ฑธ๋ฆด ์ˆ˜ ์žˆ๋‹ค.
  • ์™€์ผ๋“œ์นด๋“œ(*.๋„๋ฉ”์ธ) ์ธ์ฆ์€ Route 53์„ ์™ธ๋ถ€ DNS๋กœ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ ์ž๋™ ๋ฐœ๊ธ‰ ๋ถˆ๊ฐ€.
  • Netlify DNS๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š์„ ๋•Œ๋Š” ์ ˆ๋Œ€ NS๋ฅผ dns1.p06.nsone.net ๋“ฑ์œผ๋กœ ๋ฐ”๊พธ์ง€ ์•Š๋Š”๋‹ค.
  • SSL ๊ฐฑ์‹ ์€ Netlify๊ฐ€ ์ž๋™ ์ฒ˜๋ฆฌํ•˜๋ฏ€๋กœ, ์ˆ˜๋™ ์žฌ๋ฐœ๊ธ‰์€ ์ •๋ง ํ•„์š”ํ•œ ๊ฒฝ์šฐ์—๋งŒ ํด๋ฆญํ•œ๋‹ค.
ย 
ย 

ยฉ 2025 dan.dev.log, All right reserved.

Built with NextJS

๐Ÿ”’ Netlify SSL ์ธ์ฆ์„œ ์ž๋™ ๊ฐฑ์‹  ์˜ค๋ฅ˜ ํ•ด๊ฒฐ ๊ธฐ๋ก (Route 53 ๊ด€๋ฆฌ ๋ฐฉ์‹) | Dan DevLog