開始使用 AKS 的 Azure 容器 Linux (ACL),方法是使用 Azure Resource Manager(ARM)模板部署 AKS 叢集。
在這個快速入門中,你將學習如何:
- 用 ACL 來建立 AKS 叢集。
- 使用ARM範本部署叢集。
- 執行一個由多個容器組成的應用程式範例,其中包含微服務和網頁前端,模擬零售情境。
Note
若要開始快速佈建 AKS 叢集,本文包含僅針對評估目的部署具有預設設定值之叢集的步驟。 在部署生產就緒叢集之前,建議您先熟悉我們的基準參考架構,考慮其如何符合您的業務需求。
Important
如果你在 AKS 上使用 Azure 容器 Linux (ACL),請務必檢視以下考量與限制:
- ACL 通常從 AKS v1.34 開始提供。
- ACL 需要啟用 Trusted Launch,並搭配安全開機和 vTPM。 無法取得非可信啟動變體。
- 在 Arm64 上,ACL 若要啟用 Trusted Launch 相容性,必須使用 Cobalt 型(v6)SKU。
-
NodeImage並且None是唯一支援的 作業系統升級通道。Unmanaged且SecurityPatch因目錄不可變/usr而與 ACL 不相容。 - 不支援工件串流。
- 不支援 Pod 沙箱。
- 不支援機密虛擬機器 (CVM)。
- 第一代虛擬機不被支援。
先決條件
- 本文章假設您對 Kubernetes 概念有基本瞭解。 如需詳細資訊,請參閱 Azure Kubernetes Services (AKS) 的 Kubernetes 核心概念。
- 如果您沒有 Azure 帳戶,請在開始之前建立 免費帳戶 。
- 確定您用來建立叢集的身分識別擁有適當的最低權限。 如需 AKS 存取和身分識別的詳細資訊,請參閱 Azure Kubernetes Service (AKS) 的存取與身分識別選項。
- 要部署 ARM 範本,你需要對你部署的資源有寫入權限,並且對
Microsoft.Resources/deployments資源類型擁有所有操作的存取權。 例如,若要部署虛擬機器,您需要Microsoft.Compute/virtualMachines/write和Microsoft.Resources/deployments/*權限。 如需角色與權限的清單,請參閱 Azure 內建角色。
從範本部署叢集之後,您可以使用 Azure CLI 或 Azure PowerShell 來連線到叢集並部署範例應用程式。
註冊所需的資源提供者
你可能需要在Azure訂閱中註冊所需的資源提供者,例如 Microsoft.ContainerService。
檢查註冊狀態
使用命令 az provider show 檢查註冊狀態。
az provider show --namespace Microsoft.ContainerService --query registrationState
註冊資源提供者
如有需要,請使用 Microsoft.ContainerService 指令註冊 az provider register 資源提供者。
az provider register --namespace Microsoft.ContainerService
建立 SSH 金鑰組
若要使用 ARM 範本建立 AKS 叢集,您必須提供 SSH 公開金鑰。 如果您需要此資源,請遵循本節中的步驟。 否則,請跳至[檢閱範本]區段。
若要存取 AKS 節點,您可以使用 SSH 金鑰組 (公用和私人) 進行連線,您可以使用 ssh-keygen 命令產生該金鑰組。 根據預設,這些檔案會建立在 ~/.ssh 目錄中。 執行 ssh-keygen 命令會覆寫任何指定位置中已經存在相同名稱的 SSH 金鑰組。 如需建立 SSH 金鑰的詳細資訊,請參閱在 Azure 中建立及管理驗證的 SSH 金鑰。
請進入 https://shell.azure.com 在瀏覽器中開啟Cloud Shell。
使用
az group create命令建立資源群組。 以下範例在美國東部地區建立一個名為 myResourceGroup 的資源群組:az group create \ --name myResourceGroup \ --location eastus用指令
az sshkey create或指令ssh-keygen建立一對 SSH 金鑰。az sshkey create --name mySSHKey --resource-group myResourceGroup或者使用
ssh-keygen建立一對 SSH 金鑰:ssh-keygen -t rsa -b 4096若要部署範本,您必須從 SSH 配對提供公開金鑰。 使用命令
az sshkey show擷取公開金鑰。az sshkey show --name mySSHKey --resource-group myResourceGroup --query publicKey
檢閱範本
以下部署使用來自 Azure Quickstart Templates 的 ARM 範本:
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"metadata": {
"_generator": {
"name": "bicep",
"version": "0.26.170.59819",
"templateHash": "14823542069333410776"
}
},
"parameters": {
"clusterName": {
"type": "string",
"defaultValue": "aks101cluster",
"metadata": {
"description": "The name of the Managed Cluster resource."
}
},
"location": {
"type": "string",
"defaultValue": "[resourceGroup().location]",
"metadata": {
"description": "The location of the Managed Cluster resource."
}
},
"dnsPrefix": {
"type": "string",
"metadata": {
"description": "Optional DNS prefix to use with hosted Kubernetes API server FQDN."
}
},
"osDiskSizeGB": {
"type": "int",
"defaultValue": 0,
"minValue": 0,
"maxValue": 1023,
"metadata": {
"description": "Disk size (in GB) to provision for each of the agent pool nodes. This value ranges from 0 to 1023. Specifying 0 will apply the default disk size for that agentVMSize."
}
},
"agentCount": {
"type": "int",
"defaultValue": 3,
"minValue": 1,
"maxValue": 50,
"metadata": {
"description": "The number of nodes for the cluster."
}
},
"agentVMSize": {
"type": "string",
"defaultValue": "standard_d2s_v3",
"metadata": {
"description": "The size of the Virtual Machine."
}
},
"linuxAdminUsername": {
"type": "string",
"metadata": {
"description": "User name for the Linux Virtual Machines."
}
},
"sshRSAPublicKey": {
"type": "string",
"metadata": {
"description": "Configure all linux machines with the SSH RSA public key string. Your key should include three parts, for example 'ssh-rsa AAAAB...snip...UcyupgH azureuser@linuxvm'"
}
}
},
"resources": [
{
"type": "Microsoft.ContainerService/managedClusters",
"apiVersion": "2026-03-01",
"name": "[parameters('clusterName')]",
"location": "[parameters('location')]",
"identity": {
"type": "SystemAssigned"
},
"properties": {
"dnsPrefix": "[parameters('dnsPrefix')]",
"agentPoolProfiles": [
{
"name": "agentpool",
"osDiskSizeGB": "[parameters('osDiskSizeGB')]",
"count": "[parameters('agentCount')]",
"vmSize": "[parameters('agentVMSize')]",
"osType": "Linux",
"osSKU": "AzureContainerLinux",
"mode": "System"
}
],
"linuxProfile": {
"adminUsername": "[parameters('linuxAdminUsername')]",
"ssh": {
"publicKeys": [
{
"keyData": "[parameters('sshRSAPublicKey')]"
}
]
}
}
}
}
],
"outputs": {
"controlPlaneFQDN": {
"type": "string",
"value": "[reference(resourceId('Microsoft.ContainerService/managedClusters', parameters('clusterName')), '2026-03-01').fqdn]"
}
}
}
ARM 樣本中定義的資源類型 Microsoft.ContainerService/managedClusters。
如需更多 AKS 範例,請參閱 AKS 快速入門範本站台。
部署範本
選取 [ 部署至 Azure ] 以登入並開啟範本。
在 自訂部署 頁面設定範本參數。 在此快速入門中,保留 作業系統磁碟大小 GB、 代理程式數量、 代理虛擬機大小及 作業系統類型的預設值。 請自行提供以下參數的數值:
- 訂用帳戶:選取 Azure 訂用帳戶。
- 資源群組:選取 [新建]。 輸入資源群組的唯一名稱 (例如 myResourceGroup),然後選擇 [確定]。
-
OS SKU: Specify AzureContainerLinux. 如果你不更新作業系統 SKU,預設是
Ubuntu。 - 位置:選取一個位置,例如 [美國東部]。
- 叢集名稱: AKS 叢集的唯一名稱,例如 myAKSCluster。
- DNS 前置詞:為您的叢集輸入唯一的 DNS 前置詞,例如 myakscluster。
- Linux 管理員使用者名稱:輸入使用 SSH 連線的使用者名稱,例如 azureuser。
- SSH 公開金鑰來源: 選取 [使用現有的公開金鑰]。
- 金鑰組名稱: 複製並貼上 SSH 金鑰組的公開部分 (預設為 ~/.ssh/id_rsa.pub 的內容)。
選取 [檢閱 + 建立]> [建立]。
建立 AKS 叢集需要幾分鐘的時間。 請等到叢集成功部署後,再移至下一個步驟。
連線至叢集
若要管理 Kubernetes 叢集,請使用 Kubernetes 命令列用戶端 kubectl。 如果您使用 Azure Cloud Shell,則 kubectl 已安裝。
若要在本機安裝和執行 kubectl ,請使用命令 az aks install-cli 。
設定
kubectl使用az aks get-credentials命令連線到 Kubernetes 叢集。 此命令會下載認證,並設定 Kubernetes CLI 來使用這些認證。az aks get-credentials \ --resource-group myResourceGroup \ --name myAKSCluster使用
kubectl get命令確認叢集的連線。 此命令會傳回叢集節點的清單。kubectl get nodes下列輸出範例會顯示上一個步驟中建立的三個節點。 確定節點的狀態為就緒:
NAME STATUS ROLES AGE VERSION aks-agentpool-12345678-vmss000000 Ready <none> 5m53s v1.32.7 aks-agentpool-12345678-vmss000001 Ready <none> 6m31s v1.32.7 aks-agentpool-12345678-vmss000002 Ready <none> 6m35s v1.32.7
部署應用程式
要部署應用程式,你使用清單檔案建立執行 AKS Store 應用程式所需的所有物件。 Kube 資訊清單檔會定義叢集所需的狀態,例如要執行哪些容器映像。 清單包含下列 Kubernetes 部署和服務:
- 市集前端:供客戶檢視產品和下單的 Web 應用程式。
- 產品服務:顯示產品資訊。
- 訂單服務:下單。
- Rabbit MQ:用於訂單佇列的訊息佇列系統。
Note
除非是針對生產環境的永續性儲存體,否則不建議執行具狀態容器,例如 Rabbit MQ。 這裡為了簡化使用這些服務,但我們建議使用管理服務,例如 Azure Cosmos DB 或 Azure 服務匯流排。
建立名為
aks-store-quickstart.yaml的檔案,然後將下列資訊清單複製進來:apiVersion: apps/v1 kind: Deployment metadata: name: rabbitmq spec: replicas: 1 selector: matchLabels: app: rabbitmq template: metadata: labels: app: rabbitmq spec: nodeSelector: "kubernetes.io/os": linux containers: - name: rabbitmq image: mcr.microsoft.com/mirror/docker/library/rabbitmq:3.10-management-alpine ports: - containerPort: 5672 name: rabbitmq-amqp - containerPort: 15672 name: rabbitmq-http env: - name: RABBITMQ_DEFAULT_USER value: "username" - name: RABBITMQ_DEFAULT_PASS value: "password" resources: requests: cpu: 10m memory: 128Mi limits: cpu: 250m memory: 256Mi volumeMounts: - name: rabbitmq-enabled-plugins mountPath: /etc/rabbitmq/enabled_plugins subPath: enabled_plugins volumes: - name: rabbitmq-enabled-plugins configMap: name: rabbitmq-enabled-plugins items: - key: rabbitmq_enabled_plugins path: enabled_plugins --- apiVersion: v1 data: rabbitmq_enabled_plugins: | [rabbitmq_management,rabbitmq_prometheus,rabbitmq_amqp1_0]. kind: ConfigMap metadata: name: rabbitmq-enabled-plugins --- apiVersion: v1 kind: Service metadata: name: rabbitmq spec: selector: app: rabbitmq ports: - name: rabbitmq-amqp port: 5672 targetPort: 5672 - name: rabbitmq-http port: 15672 targetPort: 15672 type: ClusterIP --- apiVersion: apps/v1 kind: Deployment metadata: name: order-service spec: replicas: 1 selector: matchLabels: app: order-service template: metadata: labels: app: order-service spec: nodeSelector: "kubernetes.io/os": linux containers: - name: order-service image: ghcr.io/azure-samples/aks-store-demo/order-service:latest ports: - containerPort: 3000 env: - name: ORDER_QUEUE_HOSTNAME value: "rabbitmq" - name: ORDER_QUEUE_PORT value: "5672" - name: ORDER_QUEUE_USERNAME value: "username" - name: ORDER_QUEUE_PASSWORD value: "password" - name: ORDER_QUEUE_NAME value: "orders" - name: FASTIFY_ADDRESS value: "0.0.0.0" resources: requests: cpu: 1m memory: 50Mi limits: cpu: 75m memory: 128Mi initContainers: - name: wait-for-rabbitmq image: busybox command: ['sh', '-c', 'until nc -zv rabbitmq 5672; do echo waiting for rabbitmq; sleep 2; done;'] resources: requests: cpu: 1m memory: 50Mi limits: cpu: 75m memory: 128Mi --- apiVersion: v1 kind: Service metadata: name: order-service spec: type: ClusterIP ports: - name: http port: 3000 targetPort: 3000 selector: app: order-service --- apiVersion: apps/v1 kind: Deployment metadata: name: product-service spec: replicas: 1 selector: matchLabels: app: product-service template: metadata: labels: app: product-service spec: nodeSelector: "kubernetes.io/os": linux containers: - name: product-service image: ghcr.io/azure-samples/aks-store-demo/product-service:latest ports: - containerPort: 3002 resources: requests: cpu: 1m memory: 1Mi limits: cpu: 1m memory: 7Mi --- apiVersion: v1 kind: Service metadata: name: product-service spec: type: ClusterIP ports: - name: http port: 3002 targetPort: 3002 selector: app: product-service --- apiVersion: apps/v1 kind: Deployment metadata: name: store-front spec: replicas: 1 selector: matchLabels: app: store-front template: metadata: labels: app: store-front spec: nodeSelector: "kubernetes.io/os": linux containers: - name: store-front image: ghcr.io/azure-samples/aks-store-demo/store-front:latest ports: - containerPort: 8080 name: store-front env: - name: VUE_APP_ORDER_SERVICE_URL value: "http://order-service:3000/" - name: VUE_APP_PRODUCT_SERVICE_URL value: "http://product-service:3002/" resources: requests: cpu: 1m memory: 200Mi limits: cpu: 1000m memory: 512Mi --- apiVersion: v1 kind: Service metadata: name: store-front spec: ports: - port: 80 targetPort: 8080 selector: app: store-front type: LoadBalancer如需 YAML 資訊清單檔案的詳細資訊,請參閱部署和 YAML 資訊清單。
如果您在本地建立並儲存 YAML 檔案,則可以選取 上傳/下載檔案 按鈕,然後從本地文件系統選取檔案,將資訊清單檔上傳至 CloudShell 裡的預設目錄。
使用
kubectl apply命令來部署應用程式,並指定 YAML 資訊清單的名稱。kubectl apply -f aks-store-quickstart.yaml下列範例輸出會顯示部署和服務:
deployment.apps/rabbitmq created service/rabbitmq created deployment.apps/order-service created service/order-service created deployment.apps/product-service created service/product-service created deployment.apps/store-front created service/store-front created
測試應用程式
使用
kubectl get pods命令檢視已部署 Pod 的狀態。 讓全部 Pod 都是Running,再繼續。kubectl get pods檢查市集前端應用程式的公用 IP 位址。 使用
kubectl get service命令搭配--watch引數來監視進度。kubectl get service store-front --watch服務的
store-front輸出一開始會顯示為擱置:NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE store-front LoadBalancer 10.0.100.10 <pending> 80:30025/TCP 4h4m當 EXTERNAL-IP 位址從暫止變成實際的公用 IP 位址時,請使用
CTRL-C停止kubectl監看處理程序。下列範例輸出顯示指派給服務的有效公用 IP 位址:
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE store-front LoadBalancer 10.0.100.10 20.62.159.19 80:30025/TCP 4h5m開啟網頁瀏覽器以存取服務的外部 IP 位址,以查看 Azure 市集應用程式的運作方式:
刪除叢集
如果您不打算進行後續的 AKS 教學課程,請清除不必要資源以避免 Azure 費用。
使用 az group delete 命令移除資源群組、容器服務和所有相關資源。
az group delete --name myResourceGroup --yes --no-wait
Note
在本快速入門中,是以系統指派的受控識別 (預設身分識別選項) 來建立 AKS 叢集。 平台會管理這個身分識別,您不需要手動移除它。
相關內容
在這個快速入門中,你部署了一個帶有 ACL for AKS 的 AKS 叢集,使用了 ARM 範本。 若要深入了解 AKS 的 ACL,請參閱 適用於 Azure Kubernetes Service (AKS) 的 Azure Container Linux (ACL)。