本文介紹了 Azure 容器執行個體 支援的 YAML 檔案的語法與屬性,該檔案用於配置容器群組。 使用 YAML 檔案在 Azure CLI 中輸入 az 容器 create 指令的群組配置。
YAML 檔案是一種方便地配置容器群組以實現可重現部署的方式。 這是使用 Resource Manager 範本或 Azure 容器執行個體 SDK 來建立或更新容器群組的簡潔替代方案。
附註
此參考適用於 Azure 容器執行個體 REST API 版本2021-10-01的 YAML 檔案。
Schema
YAML 檔案的結構如下,並附有註解以突顯關鍵屬性。 關於此結構中屬性的描述,請參見 屬性值 章節。
name: string # Name of the container group
apiVersion: '2021-10-01'
location: string
tags: {}
identity:
type: string
userAssignedIdentities: {}
properties: # Properties of container group
containers: # Array of container instances in the group
- name: string # Name of an instance
properties: # Properties of an instance
image: string # Container image used to create the instance
command:
- string
ports: # External-facing ports exposed on the instance, must also be set in group ipAddress property
- protocol: string
port: integer
environmentVariables:
- name: string
value: string
secureValue: string
resources: # Resource requirements of the instance
requests:
memoryInGB: number
cpu: number
gpu:
count: integer
sku: string
limits:
memoryInGB: number
cpu: number
gpu:
count: integer
sku: string
volumeMounts: # Array of volume mounts for the instance
- name: string
mountPath: string
readOnly: boolean
livenessProbe:
exec:
command:
- string
httpGet:
httpHeaders:
- name: string
value: string
path: string
port: integer
scheme: string
initialDelaySeconds: integer
periodSeconds: integer
failureThreshold: integer
successThreshold: integer
timeoutSeconds: integer
readinessProbe:
exec:
command:
- string
httpGet:
httpHeaders:
- name: string
value: string
path: string
port: integer
scheme: string
initialDelaySeconds: integer
periodSeconds: integer
failureThreshold: integer
successThreshold: integer
timeoutSeconds: integer
imageRegistryCredentials: # Credentials to pull a private image
- server: string
username: string
password: string
identity: string
identityUrl: string
restartPolicy: string
ipAddress: # IP address configuration of container group
ports:
- protocol: string
port: integer
type: string
ip: string
dnsNameLabel: string
autoGeneratedDomainNameLabelScope: string
osType: string
volumes: # Array of volumes available to the instances
- name: string
azureFile:
shareName: string
readOnly: boolean
storageAccountName: string
storageAccountKey: string
emptyDir: {}
secret: {}
gitRepo:
directory: string
repository: string
revision: string
diagnostics:
logAnalytics:
workspaceId: string
workspaceKey: string
workspaceResourceId: string
logType: string
metadata: {}
subnetIds: # Subnet to deploy the container group into
- id: string
name: string
dnsConfig: # DNS configuration for container group
nameServers:
- string
searchDomains: string
options: string
sku: string # SKU for the container group
encryptionProperties:
vaultBaseUrl: string
keyName: string
keyVersion: string
initContainers: # Array of init containers in the group
- name: string
properties:
image: string
command:
- string
environmentVariables:
- name: string
value: string
secureValue: string
volumeMounts:
- name: string
mountPath: string
readOnly: boolean
屬性值
以下表格說明了你需要在結構中設定的值。
Microsoft。ContainerInstance/containerGroups 物件
| 名稱 |
類型 |
Required |
價值 |
| 名字 |
字串 |
Yes |
容器群組的名稱。 |
| apiVersion |
列舉 |
Yes |
2021-10-01(最新日期)、2021-09-01、2021-07-01、2021-03-01、2020-11-01、2019-12-01、2018-10-01、2018-09-01、2018-07-01、2018-06-01、2018-04-01 |
| 位置 |
字串 |
No |
資源位置。 |
| tags |
物件 |
No |
資源標記。 |
| 身分識別 |
物件 |
No |
如果已設定,容器群組的身分識別。
-
ContainerGroupIdentity 物件 |
| 屬性 |
物件 |
Yes |
ContainerGroupProperties 物件 |
ContainerGroupIdentity 物件
| 名稱 |
類型 |
Required |
價值 |
| 型別 |
列舉 |
No |
用於容器群組的身分識別類型。 類型 'SystemAssigned, UserAssigned' 包含隱含建立的身分識別和一組使用者指派的身分識別。 型別「None」會移除容器群組中的任何身份。 - SystemAssigned、UserAssigned、SystemAssigned、UserAssigned、無 |
| userAssignedIdentities |
物件 |
No |
與容器群組相關聯的使用者身分識別清單。 使用者身份字典的鍵參考是 Azure Resource Manager 的資源 ID,格式為:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'. |
ContainerGroupProperties 物件
容器物件
ImageRegistryCredential 物件
| 名稱 |
類型 |
Required |
價值 |
| 伺服器 |
字串 |
Yes |
沒有通訊協定的 Docker 映射登錄伺服器,例如 「HTTP」 和 「HTTPs」。 |
| 使用者名稱 |
字串 |
No |
私人登錄的用戶名稱。 |
| 密碼 |
字串 |
No |
私人登錄的密碼。 |
| 身分識別 |
字串 |
No |
用於驗證的使用者指派管理身份的資源 ID。 系統指派的管理身份不支援 ACR 映像拉取。 |
| identityUrl 的 |
字串 |
No |
私人登錄的識別 URL。 |
IpAddress 物件
| 名稱 |
類型 |
Required |
價值 |
| ports |
陣列 |
Yes |
容器群組上公開的埠清單。
-
埠物件 |
| 型別 |
列舉 |
Yes |
指定該 IP 是否暴露於公共網際網路或私人虛擬網路。 - 公立或私立 |
| IP 位址 |
字串 |
No |
公開至公用因特網的IP。 |
| dnsNameLabel |
字串 |
No |
IP 的 Dns 名稱標籤。 |
體積物件
ContainerGroupDiagnostics 物件
ContainerGroupSubnetIds 物件
| 名稱 |
類型 |
Required |
價值 |
| id |
字串 |
Yes |
子網的識別碼。 |
| 名字 |
字串 |
No |
子網的名稱。 |
DnsConfiguration 物件
| 名稱 |
類型 |
Required |
價值 |
| 名稱伺服器 |
陣列 |
Yes |
容器群組的 DNS 伺服器。 - 字串 |
| 搜索域 |
字串 |
No |
容器群組中主機名查閱的 DNS 搜尋網域。 |
| options |
字串 |
No |
容器群組的 DNS 選項。 |
EncryptionProperties 物件
| 名稱 |
類型 |
Required |
價值 |
| vaultBaseUrl 的 |
字串 |
Yes |
keyvault 基底 URL。 |
| 鍵名稱 |
字串 |
Yes |
加密金鑰名稱。 |
| keyVersion |
字串 |
Yes |
加密金鑰版本。 |
InitContainerDefinition 物件
ContainerProperties 物件
埠物件
| 名稱 |
類型 |
Required |
價值 |
| 通訊協定 |
列舉 |
No |
與埠相關聯的通訊協定。 - TCP 或 UDP |
| 傳輸埠 |
整數 |
Yes |
連接埠號碼。 |
AzureFileVolume object
| 名稱 |
類型 |
Required |
價值 |
| shareName |
字串 |
Yes |
要掛接為磁碟區的 Azure 檔案共享名稱。 |
| 唯讀 |
布爾值 |
No |
旗標,指出掛接為磁碟區的 Azure 檔案共用是否為唯讀。 |
| storageAccountName |
字串 |
Yes |
包含 Azure 檔案共用的記憶體帳戶名稱。 |
| storageAccountKey |
字串 |
No |
用來存取 Azure 檔案共用的記憶體帳戶存取金鑰。 |
GitRepoVolume 物件
| 名稱 |
類型 |
Required |
價值 |
| 目錄 |
字串 |
No |
目標目錄名稱。 不得包含或開頭為 『..』。 若提供 '.',則磁碟區目錄即為 git 儲存庫。 否則,若有指定,該磁碟區會包含帶有名稱的子目錄中的 git 儲存庫。 |
| 存放庫 |
字串 |
Yes |
存放庫 URL |
| 修訂 |
字串 |
No |
認可指定修訂的哈希。 |
LogAnalytics 物件
| 名稱 |
類型 |
Required |
價值 |
| workspaceId |
字串 |
Yes |
日誌分析用的工作區 ID |
| workspaceKey |
字串 |
Yes |
記錄分析的工作區金鑰 |
| 工作區資源ID |
字串 |
No |
日誌分析用的工作區資源 ID |
| logType |
列舉 |
No |
要使用的記錄類型。 - ContainerInsights 或 ContainerInstanceLogs |
| 中繼資料 |
物件 |
No |
記錄分析的元數據。 |
InitContainerPropertiesDefinition 物件
| 名稱 |
類型 |
Required |
價值 |
| 圖片 |
字串 |
No |
init 容器的映像。 |
| command |
陣列 |
No |
在 exec 表單的 init 容器內執行的命令。 - 字串 |
| environmentVariables |
陣列 |
No |
在 init 容器中設定的環境變數。
-
EnvironmentVariable 物件 |
| volumeMounts |
陣列 |
No |
磁碟區掛接可供 init 容器使用。
-
VolumeMount 物件 |
ContainerPort 物件
| 名稱 |
類型 |
Required |
價值 |
| 通訊協定 |
列舉 |
No |
與埠相關聯的通訊協定。 - TCP 或 UDP |
| 傳輸埠 |
整數 |
Yes |
容器群組內公開的埠號碼。 |
EnvironmentVariable 物件
| 名稱 |
類型 |
Required |
價值 |
| 名字 |
字串 |
Yes |
環境變數的名稱。 |
| value |
字串 |
No |
環境變數的值。 |
| secureValue 安全型 |
字串 |
No |
安全環境變數的值。 |
ResourceRequirements 物件
VolumeMount 物件
| 名稱 |
類型 |
Required |
價值 |
| 名字 |
字串 |
Yes |
磁碟區掛接的名稱。 |
| mountPath |
字串 |
Yes |
容器內應掛接磁碟區的路徑。 不得包含冒號 (:)。 |
| 唯讀 |
布爾值 |
No |
指出磁碟區掛接是否為唯讀的旗標。 |
ContainerProbe 物件
| 名稱 |
類型 |
Required |
價值 |
| exec |
物件 |
No |
執行探測指令 - ContainerExec 物件 |
| httpGet |
物件 |
No |
Http Get 設定用來探測 - ContainerHttpGet 物件 |
| initialDelaySeconds |
整數 |
No |
初始延遲秒。 |
| periodSeconds (週期秒) |
整數 |
No |
句點秒數。 |
| failureThreshold |
整數 |
No |
失敗臨界值。 |
| 成功閾值 |
整數 |
No |
成功臨界值。 |
| timeoutSeconds |
整數 |
No |
逾時秒數。 |
ResourceRequests 物件
| 名稱 |
類型 |
Required |
價值 |
| memoryInGB |
number |
Yes |
此容器實例的 GB 記憶體要求。 |
| cpu |
number |
Yes |
這個容器實例的CPU要求。 |
| gpu |
物件 |
No |
這個容器實例的 GPU 要求。
-
GPU 資源物件 |
ResourceLimits 物件
| 名稱 |
類型 |
Required |
價值 |
| memoryInGB |
number |
No |
此容器實例的 GB 記憶體限制。 |
| cpu |
number |
No |
這個容器實例的CPU限制。 |
| gpu |
物件 |
No |
此容器實例的 GPU 限制。
-
GPU 資源物件 |
ContainerExec 物件
| 名稱 |
類型 |
Required |
價值 |
| command |
陣列 |
No |
在容器內執行的命令。 - 字串 |
ContainerHttpGet 物件
| 名稱 |
類型 |
Required |
價值 |
| 路徑 |
字串 |
No |
探查的路徑。 |
| 傳輸埠 |
整數 |
Yes |
要探查的埠號碼。 |
| scheme |
列舉 |
No |
配置。 - HTTP 或 https |
| HTTP 標頭 |
物件 |
No |
探測中包含的 HTTP 標頭。
-
HttpHeaders 物件 |
| 名稱 |
類型 |
Required |
價值 |
| 名字 |
字串 |
No |
標頭名稱。 |
| value |
字串 |
No |
標頭的值。 |
Important
K80 和 P100 GPU SKU 將於 2023 年 8 月 31 日前退役。 這是因為底層虛擬機(NC Series 和 NCv2 系列)已經退役。雖然 V100 SKU 會提供,但建議改用 Azure Kubernetes Service。 GPU 資源尚未完全支援,不應用於生產工作負載。 請使用以下資源立即遷移至 AKS:如何遷移至 AKS。
GPU 資源物件
| 名稱 |
類型 |
Required |
價值 |
| count |
整數 |
Yes |
GPU 資源的計數。 |
| sku |
列舉 |
Yes |
GPU 資源的 SKU。 - V100 |
下一步
請參考教學「 使用 YAML 檔案部署多容器群組」。
請參考使用 YAML 檔案部署 虛擬網路 容器群組或掛 載外部磁碟區的範例。