適用於: ✔️ AKS 自動化 ✔️ AKS 標準
通常我們會使用管線在 Azure Kubernetes Service (AKS) 叢集上建置和部署映像。 雖然非常適合用來建立映像,但此程序通常不會考慮留下的過時映像,而這可能會導致叢集節點上的映像高載。 這些映像可能包含弱點,這可能會造成安全性問題。 若要消除叢集中的安全性風險,您可以清除這些未參考的映像。 手動清除映像可能需要大量時間。 Image Cleaner 會執行自動映像識別和移除,以降低過時映像的風險,並減少清除映像所需的時間。
AKS Automatic 是大多數 AKS 工作負載建議採用、適合正式環境使用的預設選項。 影像清理器預設在 AKS 自動叢集中,幫助移除帶有漏洞的未使用映像檔。
在 AKS Standard 叢集中,影像清理是可選的,且你可以明確啟用。
欲了解更多關於 AKS 自動的資訊,請參閱 What is Azure Kubernetes Service (AKS) Automatic?
附註
Image Cleaner 是以 Eraser 為基礎的功能。 在 AKS 上,特徵名稱與屬性名稱為 Image Cleaner,而相關的影像清潔器膠囊名稱則包含 Eraser。
AKS Automatic 與 AKS Standard 的行為
先決條件
- Azure 訂用帳戶。 如果您沒有 Azure 訂用帳戶,您可以建立免費帳戶。
- 若要透過 Azure CLI 進行 AKS Standard 設定,需使用 Azure CLI 2.49.0 或更新版本。 執行
az --version來尋找您的版本。 如果您需要安裝或升級,請參閱安裝 Azure CLI。
限制
Image Cleaner 尚未支援 Windows 節點集區或 AKS 虛擬節點。
Image Cleaner 的運作方式
當你在叢集上啟用映像清理器時,它會部署一個名為 eraser-controller-manager 的控制器管理員 Pod。
影像清理器支援自動與手動清理模式。
AKS Standard 的設定選項
在 AKS Standard 搭配 Azure CLI 設定 Image Cleaner 時,請使用這些選項。
| 名稱 | 描述 | 必要 |
|---|---|---|
--enable-image-cleaner |
為 AKS 叢集啟用映像清理工具 | 是的,除非你明確指定停用 |
--disable-image-cleaner |
停用 AKS 叢集的映像清理程式 | 是的,除非你特別指定啟用 |
--image-cleaner-interval-hours |
排定跑步的時間間隔以小時為單位。 Azure CLI 預設為一週。 最少要24小時。 最多三個月。 | Azure CLI 不需要;ARM 範本或其他客戶端則需要 |
附註
如果你停用映像清理器,之後又重新啟用,但沒有明確傳遞設定,之前的設定值會被重複使用。
自動模式
當你部署 eraser-controller-manager時,映像清理器會自動執行以下操作:
- 開始清理,並為每個節點建立
eraser-aks-xxxxx工作艙。 - 使用 收藏容器 收集未使用的影像。
- 使用 trivy-scanner 容器搭配 trivy 掃描漏洞。
- 使用 移除器 容器移除未使用的有漏洞的影像。
- 完成後刪除背景工作 Pod。
- 根據
--image-cleaner-interval-hours排定下一次清理作業。
手動模式
您可以藉由定義 CRD 物件 ImageList 手動觸發清除。 這會觸發 eraser-contoller-manager ,為每個節點建立 eraser-aks-xxxxx 背景工作Pod,並完成手動移除程式。
附註
停用 Image Cleaner 之後,舊設定仍存在。 這表示如果您再次啟用此功能而未明確傳遞設定,則會使用現有的值,而不是預設值。
在 AKS 自動版和 AKS 標準版上使用映像清理工具
AKS 自動化系统
Image Cleaner 已預先設定於 AKS Automatic 叢集上,而這類叢集是大多數 AKS 工作負載建議採用、可用於正式環境的預設選項。 你不需要另外執行啟用指令。
要建立 AKS 自動叢集,請參見 建立 AKS 自動叢集。
當您想要針對性修復或操作驗證時,請使用本文中的手動清理與監控指引。
AKS 標準:在新的叢集上啟用
在新的 AKS Standard 叢集上使用 az aks create 帶有 --enable-image-cleaner 參數的指令啟用影像清理器。
az aks create \
--resource-group myResourceGroup \
--name myManagedCluster \
--enable-image-cleaner \
--generate-ssh-keys
AKS 標準:在現有叢集上啟用
請使用 az aks update 指令在現有的 AKS Standard 叢集上啟用影像清理器。
az aks update \
--resource-group myResourceGroup \
--name myManagedCluster \
--enable-image-cleaner
AKS 標準:對新叢集或現有叢集進行更新間隔
使用 --image-cleaner-interval-hours 參數更新新建或現有 AKS Standard 叢集的影像清理間隔。
# Create a new cluster with specifying the interval
az aks create \
--resource-group myResourceGroup \
--name myManagedCluster \
--enable-image-cleaner \
--image-cleaner-interval-hours 48 \
--generate-ssh-keys
# Update the interval on an existing cluster
az aks update \
--resource-group myResourceGroup \
--name myManagedCluster \
--enable-image-cleaner \
--image-cleaner-interval-hours 48
使用 Image Cleaner 手動移除映像
重要事項
name 必須設定為 imagelist。
使用下列 kubectl apply 命令手動移除映像。 本範例會移除未使用的 docker.io/library/alpine:3.7.3 映像。
cat <<EOF | kubectl apply -f -
apiVersion: eraser.sh/v1
kind: ImageList
metadata:
name: imagelist
spec:
images:
- docker.io/library/alpine:3.7.3
EOF
手動清除是一次性作業,只有在建立新的 imagelist 或變更現有的 imagelist 時才會觸發。 刪除映像之後,將不會自動刪除 imagelist。
如果您需要觸發另一次手動清除,您必須建立新的 imagelist 或變更現有的映像。 如果您要再次移除同一個映像,您必須建立新的 imagelist。
刪除現有的 ImageList 並建立新的 ImageList
使用
imagelist命令移除舊的kubectl delete。kubectl delete ImageList imagelist使用同一個映像名稱建立新的
imagelist。 下列範例會使用與上一個範例相同的映像。cat <<EOF | kubectl apply -f - apiVersion: eraser.sh/v1 kind: ImageList metadata: name: imagelist spec: images: - docker.io/library/alpine:3.7.3 EOF
修改現有的 ImageList
使用 imagelist 命令修改現有的 kubectl edit。
kubectl edit ImageList imagelist
# Add a new image to the list
apiVersion: eraser.sh/v1
kind: ImageList
metadata:
name: imagelist
spec:
images:
docker.io/library/python:alpine3.18
使用手動模式時,eraser-aks-xxxxx Pod 會在工作完成後的 10 分鐘內刪除。
映像排除清單
排除清單中指定的映像不會從叢集移除。 Image Cleaner 支援系統和使用者定義的排除清單。 不支援編輯系統排除清單。
檢查系統排除清單
使用下列 kubectl get 命令檢查系統排除清單。
kubectl get -n kube-system configmap eraser-system-exclusion -o yaml
建立使用者定義的排除清單
建立範例 JSON 檔案以包含排除的映像。
cat > sample.json <<EOF {"excluded": ["excluded-image-name"]} EOF使用下列
configmap和kubectl create命令,使用範例 JSON 檔案建立kubectl label。kubectl create configmap excluded --from-file=sample.json --namespace=kube-system kubectl label configmap excluded eraser.sh/exclude.list=true -n kube-system
在 AKS Standard 上停用影像清理器
使用 az aks update 帶有 --disable-image-cleaner 參數的指令在 AKS Standard 叢集上停用影像清理器。
az aks update \
--resource-group myResourceGroup \
--name myManagedCluster \
--disable-image-cleaner
常見問題 (FAQs)
AKS 自動版預設有啟用影像清理功能嗎?
Yes. 影像清理器已預先設定在 AKS 自動叢集上。
我需要在 AKS Automatic 上執行 Image Cleaner 的啟用指令嗎?
否。 請使用 AKS Standard 的啟用指令。
如何檢查 Image Cleaner 使用哪個版本?
kubectl describe configmap -n kube-system eraser-manager-config | grep tag -C 3
除了 Trivy 掃描器之外,Image Cleaner 是否支援其他弱點掃描器?
否。
我可以指定要清除映像的弱點層級嗎?
否。 弱點層級的預設設定包括:
-
LOW, -
MEDIUM, -
HIGH和 CRITICAL
您無法自訂預設設定。
如何檢閱 Image Cleaner 已清除的映像?
映射記錄會儲存在 eraser-aks-xxxxx 背景工作Pod中。
eraser-aks-xxxxx 運作時,您可以執行下列命令來檢視刪除記錄:
kubectl logs -n kube-system <worker-pod-name> -c collector
kubectl logs -n kube-system <worker-pod-name> -c trivy-scanner
kubectl logs -n kube-system <worker-pod-name> -c remover
eraser-aks-xxxxx Pod 會在工作完成後的 10 分鐘內刪除。 您可以遵循下列步驟來啟用 Azure 監視器附加元件,並使用容器深入解析 Pod 記錄資料表。 此後,系統會儲存歷程記錄,即使已刪除 eraser-aks-xxxxx,您也可以檢閱記錄檔。
請確保您的叢集啟用 Azure 監視器。 如需詳細步驟,請參閱在 AKS 叢集上啟用容器深入解析。
預設情況下,該命名空間中執行
kube-system容器的日誌不會被收集。 在 ConfigMap 中,從exclude_namespaces移除kube-system命名空間,並套用該 ConfigMap 以啟用這些日誌的收集功能。 如需詳細資料,請參閱設定容器深入解析資料收集。使用
az aks show命令取得 Log Analytics 資源識別碼。az aks show --resource-group myResourceGroup --name myManagedCluster幾分鐘後,命令會傳回解決方案的 JSON 格式資訊,包括工作區資源識別碼:
"addonProfiles": { "omsagent": { "config": { "logAnalyticsWorkspaceResourceID": "/subscriptions/<WorkspaceSubscription>/resourceGroups/<DefaultWorkspaceRG>/providers/Microsoft.OperationalInsights/workspaces/<defaultWorkspaceName>" }, "enabled": true } }在 Azure 入口網站中,搜尋工作空間資源 ID,然後選擇日誌。
複製以下其中一項查詢並貼上到查詢視窗。
如果您的叢集使用 ContainerLogV2 結構描述,請使用下列查詢。 如果你還在用
ContainerLog,升級到 ContainerLogV2。ContainerLogV2 | where PodName startswith "eraser-aks-" and PodNamespace == "kube-system" | project TimeGenerated, PodName, LogMessage, LogSource如果你想繼續使用
ContainerLog,請改用以下查詢:let startTimestamp = ago(1h); KubePodInventory | where TimeGenerated > startTimestamp | project ContainerID, PodName=Name, Namespace | where PodName startswith "eraser-aks-" and Namespace == "kube-system" | distinct ContainerID, PodName | join ( ContainerLog | where TimeGenerated > startTimestamp ) on ContainerID // at this point before the next pipe, columns from both tables are available to be "projected". Due to both // tables having a "Name" column, we assign an alias as PodName to one column which we actually want | project TimeGenerated, PodName, LogEntry, LogEntrySource | summarize by TimeGenerated, LogEntry | order by TimeGenerated desc ```
選取 [執行]。 任何已刪除的映像記錄會出現在 [結果] 區域中。
相關內容
- 了解更多關於AKS Automatic的資訊,請參閱What is Azure Kubernetes Service (AKS) Automatic?
- 使用建立 Azure Kubernetes Service (AKS) Automatic 叢集,建立可用於正式生產環境的 AKS Automatic 叢集。