透過 Azure Container Registry (ACR) 上 Azure Kubernetes Service (AKS) 的成品串流功能縮短部署時間

大型容器映像檔會增加影像拉取時間並延遲工作負載部署。 Artifact Streaming 允許你將容器映像從 Azure Container Registry(ACR)串流到 Azure Kubernetes Service (AKS)。 AKS 只會提取 Pod 初次啟動所需的層,縮短部署工作負載所需的時間。

本文說明如何在 AKS 節點集區上啟用及停用 Artifact Streaming 功能,以從 ACR 串流成品。

必要條件

局限性

  • 僅支援採用 Linux AMD64 架構的映像檔。
  • 不支援基於 Windows 的容器映像檔和 ARM64 映像檔。
  • 僅支援 AMD64 架構以支援多架構映像。
  • AKS 中基於 Ubuntu 的節點池必須使用 Ubuntu 版本 20.04 或更高版本。
  • 僅支援進階 SKU 的 ACR 登錄。
  • 不支援 CMK(Customer-Managed Keys)登錄檔。
  • 不支援 Kubernetes regcred,例如 imagePullSecrets。 使用非 Entra 範圍對應權杖憑證或 ACR 管理員使用者憑證從 ACR 提取映像時,預設使用非成品串流提取,即使節點集區和映像已啟用串流傳輸。
  • Artifact Streaming 只支援以標籤拉取圖片。 Artifact Streaming 的運作方式,是將依標籤擷取的映像檔解析為該映像檔的串流版本。 如果是依摘要拉取映像檔,就無法使用 Artifact Streaming。

在 ACR 上啟用成品串流

  1. 使用 az group create 命令建立 Azure 資源群組來保存您的 ACR 實例。

    az group create --name myStreamingTest --location westus
    
  2. 用 az acr create 帶有 --sku Premium 旗標的指令建立一個新的高級 SKU ACR。

    az acr create --resource-group myStreamingTest --name mystreamingtest --sku Premium
    
  3. 使用 az configure 命令,為您的訂用帳戶設定預設 ACR 執行個體。

    az configure --defaults acr="mystreamingtest"
    
  4. 使用 az acr import 命令將映像推送或匯入登錄。

    az acr import --source docker.io/jupyter/all-spark-notebook --repository jupyter/all-spark-notebook
    
  5. 使用 az acr artifact-streaming create 命令從映像建立串流成品。

    az acr artifact-streaming create --image jupyter/all-spark-notebook:latest
    
  6. 使用 az acr manifest list-referrers 命令確認產生的成品串流。

    az acr manifest list-referrers --name jupyter/all-spark-notebook:latest
    

在 AKS 上啟用成品串流

你可以在 AKS 叢集的新節點或現有節點池上啟用 Artifact Streaming,並整合 ACR。

附註

如果你的 AKS 叢集沒有整合 Premium Tier ACR,就無法在 AKS 上使用 Artifact Streaming。

附註

啟用 節點自動配置(NAP )的叢集可利用 spec.artifactStreaming.enabledAKSNodeClass CRD 欄位啟用工件串流。 將此欄位設為 true 啟用任何與此 AKSNodeClass CRD 相關的新或現有 NAP 管理節點的工件串流。

在新節點集區上啟用成品串流

用 az aks nodepool add 帶有 --enable-artifact-streaming 旗標的指令建立一個啟用 Artifact Streaming 的新 AKS 節點池。

az aks nodepool add \
    --resource-group myResourceGroup \
    --cluster-name myAKSCluster \
    --name myNodePool \
    --enable-artifact-streaming

在現有的節點池上啟用工件串流

在現有的 AKS 節點池上使用 az aks nodepool update 帶有 --enable-artifact-streaming 旗標的指令啟用 Artifact Streaming。

az aks nodepool update \
    --resource-group myResourceGroup \
    --cluster-name myAKSCluster \
    --name myNodePool \
    --enable-artifact-streaming

在現有節點池中停用 Artifact Stream

使用 az aks nodepool update 帶有 --disable-artifact-streaming 旗標的指令在現有的 AKS 節點池上停用 Artifact Streaming。

az aks nodepool update \
    --resource-group myResourceGroup \
    --cluster-name myAKSCluster \
    --name myNodePool \
    --disable-artifact-streaming

檢查 Artifact Streaming 啟用狀態

使用 az aks nodepool show 命令,並將 --query 旗標設為 artifactStreamingProfile,以檢查 AKS 節點池是否已啟用 Artifact Streaming。

az aks nodepool show \
    --resource-group myResourceGroup \
    --cluster-name myAKSCluster \
    --name myNodePool \
    --query artifactStreamingProfile

在輸出中檢查 Enabled 欄位。 true 表示已啟用 Artifact Streaming,而 false Artifact Streaming 則是被關閉。

本文說明如何在 AKS 節點池啟用與停用 Artifact Stream,以從 ACR 串流產件並縮短部署時間。 若要深入瞭解在 AKS 中使用容器映像,請參閱 AKS 中容器映像管理和安全性的最佳做法。