大型容器映像檔會增加影像拉取時間並延遲工作負載部署。 Artifact Streaming 允許你將容器映像從 Azure Container Registry(ACR)串流到 Azure Kubernetes Service (AKS)。 AKS 只會提取 Pod 初次啟動所需的層,縮短部署工作負載所需的時間。
本文說明如何在 AKS 節點集區上啟用及停用 Artifact Streaming 功能,以從 ACR 串流成品。
必要條件
- Azure 訂用帳戶。 如果您沒有 Azure 訂用帳戶,您可以建立免費帳戶。
- 在 ACR 上啟用工件串流。
- Azure CLI 版本 2.87.0 或更後版本。 執行
az --version來尋找您的版本。 如果您需要安裝或升級,請參閱 安裝 Azure CLI。 - 此功能需要 Kubernetes 1.25 版或更新版本。 若要檢查您的 AKS 叢集版本,請參閱檢查是否有可用的 AKS 叢集升級。
- 已與 ACR 整合的 AKS 叢集。 如果您沒有帳戶,您可以使用從 AKS 使用 ACR 驗證來建立一個。
- 必須具備 Azure Kubernetes Service Contributor Role,才能修改節點集區組態。
局限性
- 僅支援採用 Linux AMD64 架構的映像檔。
- 不支援基於 Windows 的容器映像檔和 ARM64 映像檔。
- 僅支援 AMD64 架構以支援多架構映像。
- AKS 中基於 Ubuntu 的節點池必須使用 Ubuntu 版本 20.04 或更高版本。
- 僅支援進階 SKU 的 ACR 登錄。
- 不支援 CMK(Customer-Managed Keys)登錄檔。
- 不支援 Kubernetes
regcred,例如imagePullSecrets。 使用非 Entra 範圍對應權杖憑證或 ACR 管理員使用者憑證從 ACR 提取映像時,預設使用非成品串流提取,即使節點集區和映像已啟用串流傳輸。 - Artifact Streaming 只支援以標籤拉取圖片。 Artifact Streaming 的運作方式,是將依標籤擷取的映像檔解析為該映像檔的串流版本。 如果是依摘要拉取映像檔,就無法使用 Artifact Streaming。
在 ACR 上啟用成品串流
使用
az group create命令建立 Azure 資源群組來保存您的 ACR 實例。az group create --name myStreamingTest --location westus用
az acr create帶有--sku Premium旗標的指令建立一個新的高級 SKU ACR。az acr create --resource-group myStreamingTest --name mystreamingtest --sku Premium使用
az configure命令,為您的訂用帳戶設定預設 ACR 執行個體。az configure --defaults acr="mystreamingtest"使用
az acr import命令將映像推送或匯入登錄。az acr import --source docker.io/jupyter/all-spark-notebook --repository jupyter/all-spark-notebook使用
az acr artifact-streaming create命令從映像建立串流成品。az acr artifact-streaming create --image jupyter/all-spark-notebook:latest使用
az acr manifest list-referrers命令確認產生的成品串流。az acr manifest list-referrers --name jupyter/all-spark-notebook:latest
在 AKS 上啟用成品串流
你可以在 AKS 叢集的新節點或現有節點池上啟用 Artifact Streaming,並整合 ACR。
附註
如果你的 AKS 叢集沒有整合 Premium Tier ACR,就無法在 AKS 上使用 Artifact Streaming。
附註
啟用 節點自動配置(NAP )的叢集可利用 spec.artifactStreaming.enabledAKSNodeClass CRD 欄位啟用工件串流。 將此欄位設為 true 啟用任何與此 AKSNodeClass CRD 相關的新或現有 NAP 管理節點的工件串流。
在新節點集區上啟用成品串流
用 az aks nodepool add 帶有 --enable-artifact-streaming 旗標的指令建立一個啟用 Artifact Streaming 的新 AKS 節點池。
az aks nodepool add \
--resource-group myResourceGroup \
--cluster-name myAKSCluster \
--name myNodePool \
--enable-artifact-streaming
在現有的節點池上啟用工件串流
在現有的 AKS 節點池上使用 az aks nodepool update 帶有 --enable-artifact-streaming 旗標的指令啟用 Artifact Streaming。
az aks nodepool update \
--resource-group myResourceGroup \
--cluster-name myAKSCluster \
--name myNodePool \
--enable-artifact-streaming
在現有節點池中停用 Artifact Stream
使用 az aks nodepool update 帶有 --disable-artifact-streaming 旗標的指令在現有的 AKS 節點池上停用 Artifact Streaming。
az aks nodepool update \
--resource-group myResourceGroup \
--cluster-name myAKSCluster \
--name myNodePool \
--disable-artifact-streaming
檢查 Artifact Streaming 啟用狀態
使用 az aks nodepool show 命令,並將 --query 旗標設為 artifactStreamingProfile,以檢查 AKS 節點池是否已啟用 Artifact Streaming。
az aks nodepool show \
--resource-group myResourceGroup \
--cluster-name myAKSCluster \
--name myNodePool \
--query artifactStreamingProfile
在輸出中檢查 Enabled 欄位。
true 表示已啟用 Artifact Streaming,而 false Artifact Streaming 則是被關閉。
相關內容
本文說明如何在 AKS 節點池啟用與停用 Artifact Stream,以從 ACR 串流產件並縮短部署時間。 若要深入瞭解在 AKS 中使用容器映像,請參閱 AKS 中容器映像管理和安全性的最佳做法。