當您建立 Azure Batch 集區時,您可以使用已啟用自動 OS 升級的節點來佈建集區。 本文說明如何使用自動OS升級來設定 Batch 集區。
為什麼要使用自動OS升級?
自動OS升級可用來在 Azure Batch 集區內實作自動作系統升級策略和控制。 以下是使用自動OS升級的一些原因:
- 安全性。 自動OS升級可確保在作系統映像內及時修補弱點和安全性問題,以增強計算資源的安全性。 它有助於防止潛在的安全性弱點對應用程式和數據構成威脅。
- 將可用性中斷降到最低。 自動OS升級可用來將OS升級期間計算節點的可用性中斷降到最低。 此功能是透過工作排程感知的升級延遲以及輪流升級支援來達成,確保工作負載的中斷降到最低。
- 彈性。 自動OS升級可讓您設定自動作系統升級策略,包括以百分比為基礎的升級協調和復原支援。 這表示您可以自定義升級策略,以符合您的特定效能和可用性需求。
- 管控。 Auto OS Upgrade 讓您掌控作業系統升級策略,確保升級部署安全且可感知工作負載。 您可以量身打造原則設定,以符合組織的特定需求。
總而言之,使用自動OS升級有助於改善安全性、將可用性中斷降到最低,併為工作負載提供更大的控制和彈性。
自動OS升級如何運作?
升級映射時,Azure Batch 集區中的 VM 會遵循與 VirtualMachineScaleSets 大致相同的工作流程。 若要深入瞭解 VirtualMachineScaleSets 自動 OS 升級程式所涉及的詳細步驟,請參閱 VirtualMachineScaleSet 頁面。
不過,如果 automaticOSUpgradePolicy.osRollingUpgradeDeferral 設定為 'true',且當批次節點正在執行工作時有可用的升級,則升級會延後,直到該節點上的所有工作都已完成為止。
注意事項
如果集區已啟用 osRollingUpgradeDeferral,其節點在升級過程中會顯示為 upgradingos 狀態。 請注意,只有在您使用 2024-02-01 或更新版本的 API 時,才會顯示 upgradingos 狀態。 如果您使用舊的 API 版本來呼叫 GetTVM/ListTVM,升級時節點會處於 重新啟動 狀態。
支援的作業系統映像
目前僅支援特定作業系統平台映像的自動升級。 如需詳細的影像清單,您可以從 VirtualMachineScaleSet 頁面取得。
需求
- 映像版本屬性必須設為最新。
- 針對 Batch 管理 API,請使用 API 版本 2024-02-01 或更高版本。 針對 Batch 服務 API,請使用 API 2024-02-01.19.0 版或更高版本。
- 請確保集區中指定的外部資源可用且為最新。 範例包括:VM 擴充功能屬性中用於初始設定承載內容的 SAS URI、儲存體帳戶中的承載內容,以及模型中對祕密的參考等等。
- 如果您使用 virtualMachineConfiguration.windowsConfiguration.enableAutomaticUpdates 屬性,此屬性必須在集區定義中設定為 'false'。 enableAutomaticUpdates 屬性會啟用虛擬機器內修補,讓「Windows Update」可在不更換 OS 磁碟的情況下套用作業系統修補程式。 啟用自動OS映像升級後,不需要透過Windows Update進行額外的修補程式。
自訂映像的其他需求
- 當映像的新版本發佈並複寫到該集區所在的區域時,這些 VM 將會升級至最新版的 Azure 計算資源庫映像。 如果未將新映射複寫至部署集區的區域,VM 實例將不會升級至最新版本。 區域映像複寫可讓您控制 VM 新映像的推出。
- 新的映像版本不應從該畫廊映像的最新版本中排除。 從畫廊映像最新版本排除的映像版本,不會透過自動 OS 映像升級推出。
設定自動OS升級
如果您想要在集區內實作自動OS升級,請務必在集區建立程式期間設定 UpgradePolicy 字段。 若要設定自動OS映射升級,請確定 集區定義中的 automaticOSUpgradePolicy.enableAutomaticOSUpgrade 屬性設定為 'true'。
注意事項
升級原則模式和自動作業系統升級原則是彼此獨立的設定,分別控制 Azure Batch 所佈建的擴展集的不同面向。 升級原則模式會決定規模集中現有執行個體的處理方式。 不過,自動 OS 升級原則 `enableAutomaticOSUpgrade` 是 OS 映像專有的,會追蹤映像發行者所做的變更,並決定映像更新時會發生什麼情況。
REST API
下列範例說明如何透過 REST API 建立具有自動 OS 升級的集區:
PUT https://management.azure.com/subscriptions/<subscriptionid>/resourceGroups/<resourcegroupName>/providers/Microsoft.Batch/batchAccounts/<batchaccountname>/pools/<poolname>?api-version=2024-02-01
要求本文
{
"name": "test1",
"type": "Microsoft.Batch/batchAccounts/pools",
"parameters": {
"properties": {
"vmSize": "Standard_d4s_v3",
"deploymentConfiguration": {
"virtualMachineConfiguration": {
"imageReference": {
"publisher": "MicrosoftWindowsServer",
"offer": "WindowsServer",
"sku": "2019-datacenter-smalldisk",
"version": "latest"
},
"nodePlacementConfiguration": {
"policy": "Zonal"
},
"nodeAgentSKUId": "batch.node.windows amd64",
"windowsConfiguration": {
"enableAutomaticUpdates": false
}
}
},
"scaleSettings": {
"fixedScale": {
"targetDedicatedNodes": 2,
"targetLowPriorityNodes": 0
}
},
"upgradePolicy": {
"mode": "Automatic",
"automaticOSUpgradePolicy": {
"disableAutomaticRollback": true,
"enableAutomaticOSUpgrade": true,
"useRollingUpgradePolicy": true,
"osRollingUpgradeDeferral": true
},
"rollingUpgradePolicy": {
"enableCrossZoneUpgrade": true,
"maxBatchInstancePercent": 20,
"maxUnhealthyInstancePercent": 20,
"maxUnhealthyUpgradedInstancePercent": 20,
"pauseTimeBetweenBatches": "PT0S",
"prioritizeUnhealthyInstances": false,
"rollbackFailedInstancesOnPolicyBreach": false
}
}
}
}
}
SDK (C#)
以下程式碼片段示範如何使用 Azure.ResourceManager.Batch 用戶端程式庫,透過 C# 程式碼建立啟用自動作業系統升級的集區。 如需 Azure.ResourceManager.Batch 的更多詳細資訊,請參閱 參考文件。
public async Task CreateUpgradePolicyPool()
{
// Authenticate
var subscriptionId = Environment.GetEnvironmentVariable("SUBSCRIPTION_ID");
DefaultAzureCredential credential = new DefaultAzureCredential();
ArmClient client = new ArmClient(credential, subscriptionId);
// Get an existing Batch account
string resourceGroupName = "testrg";
string accountName = "testaccount";
ResourceIdentifier batchAccountResourceId = BatchAccountResource.CreateResourceIdentifier(subscriptionId, resourceGroupName, accountName);
BatchAccountResource batchAccount = client.GetBatchAccountResource(batchAccountResourceId);
// get the collection of this BatchAccountPoolResource
BatchAccountPoolCollection collection = batchAccount.GetBatchAccountPools();
// Define the pool
string poolName = "testpool";
BatchAccountPoolData data = new BatchAccountPoolData()
{
VmSize = "Standard_d4s_v3",
DeploymentConfiguration = new BatchDeploymentConfiguration()
{
VmConfiguration = new BatchVmConfiguration(new BatchImageReference()
{
Publisher = "MicrosoftWindowsServer",
Offer = "WindowsServer",
Sku = "2019-datacenter-smalldisk",
Version = "latest",
},
nodeAgentSkuId: "batch.node.windows amd64")
{
NodePlacementPolicy = BatchNodePlacementPolicyType.Zonal,
IsAutomaticUpdateEnabled = false
},
},
ScaleSettings = new BatchAccountPoolScaleSettings()
{
FixedScale = new BatchAccountFixedScaleSettings()
{
TargetDedicatedNodes = 2,
TargetLowPriorityNodes = 0,
},
},
UpgradePolicy = new UpgradePolicy()
{
Mode = UpgradeMode.Automatic,
AutomaticOSUpgradePolicy = new AutomaticOSUpgradePolicy()
{
DisableAutomaticRollback = true,
EnableAutomaticOSUpgrade = true,
UseRollingUpgradePolicy = true,
OSRollingUpgradeDeferral = true
},
RollingUpgradePolicy = new RollingUpgradePolicy()
{
EnableCrossZoneUpgrade = true,
MaxBatchInstancePercent = 20,
MaxUnhealthyInstancePercent = 20,
MaxUnhealthyUpgradedInstancePercent = 20,
PauseTimeBetweenBatches = "PT0S",
PrioritizeUnhealthyInstances = false,
RollbackFailedInstancesOnPolicyBreach = false,
}
}
};
ArmOperation<BatchAccountPoolResource> lro = await collection.CreateOrUpdateAsync(WaitUntil.Completed, poolName, data);
BatchAccountPoolResource result = lro.Value;
// the variable result is a resource, you could call other operations on this instance as well
// but just for demo, we get its data from this resource instance
BatchAccountPoolData resourceData = result.Data;
// for demo we just print out the id
Console.WriteLine($"Succeeded on id: {resourceData.Id}");
}
常見問題集
如果我啟用自動OS升級,我的工作是否會中斷?
當 automaticOSUpgradePolicy.osRollingUpgradeDeferral 設定為 'true' 時,工作將不會中斷。 在此情況下,升級將會延後,直到節點閑置為止。 否則,不論節點目前是否正在執行工作,都會在收到新的OS版本時升級。 因此,我們強烈建議啟用 automaticOSUpgradePolicy.osRollingUpgradeDeferral。