本文提供兩個 Azure CLI 腳本,用於從快照建立受管理磁碟。 第一個腳本建立一個由平台管理的金鑰管理的受管理磁碟,第二個腳本則建立一個由客戶管理的金鑰的受管理磁碟。 當你從各自的快照建立作業系統和資料磁碟後,你可以用這些磁碟建立虛擬機或還原現有虛擬機的資料。
如果您沒有 Azure 帳戶,請在開始之前建立 免費帳戶 。
先決條件
在 Azure Cloud Shell 中使用 Bash 環境。 如需詳細資訊,請參閱開始使用 Azure Cloud Shell。
若要在本機執行 CLI 參考命令,請安裝 (部分機器翻譯) Azure CLI。 若您在 Windows 或 macOS 上執行,請考慮在 Docker 容器中執行 Azure CLI。 如需詳細資訊,請參閱如何在 Docker 容器中執行 Azure CLI。
如果您使用的是本機安裝,請使用 az login 命令,透過 Azure CLI 來登入。 請遵循您終端機上顯示的步驟,以完成驗證流程。 如需其他登入選項,請參閱 使用 Azure CLI 向 Azure 進行驗證。
出現提示時,請在第一次使用時安裝 Azure CLI 延伸模組。 如需擴充功能的詳細資訊,請參閱 使用和管理 Azure CLI 的擴充功能。
執行 az version (部分機器翻譯) 以尋找已安裝的版本和相依程式庫。 若要升級至最新版本,請執行 az upgrade。
從快照建立管理磁碟
啟動 Azure Cloud Shell
Azure Cloud Shell 是免費的互動式 Shell,可讓您用來執行本文中的步驟。 它具有預先安裝和設定的共用 Azure 工具,可與您的帳戶搭配使用。
若要開啟 Cloud Shell,只要選取程式碼區塊右上角的 [試試看] 即可。 您也可以移至 https://shell.azure.com,從另一個瀏覽器索引標籤啟動 Cloud Shell。
當開啟 Cloud Shell 時,請確認已為您的環境選取 Bash。 後續的工作階段將會在 Bash 環境中使用 Azure CLI,請選取 [複製] 以複製程式碼區塊,並將其貼到 Cloud Shell 中,然後按 Enter 鍵加以執行。
登入 Azure
系統會在登入的初始帳戶下自動驗證 Cloud Shell。 使用下列指令碼使用不同的訂用帳戶登入,並將 subscriptionId 取代為您的 Azure 訂用帳戶識別碼。
如果您沒有 Azure 帳戶,請在開始之前建立 免費帳戶 。
subscription="subscriptionId" # Set Azure subscription ID here
az account set -s $subscription # ...or use 'az login'
如需詳細資訊,請參閱設定使用中訂用帳戶 (部分機器翻譯) 或以互動方式登入 (部分機器翻譯)。
具有平台代控金鑰的磁碟
使用此腳本建立一個由平台管理的金鑰管理的磁碟。 提供訂閱、資源群組、來源快照、新磁碟名稱、磁碟大小及儲存類型。 對於 Premium SSD v2 和 Ultra Disk,也請提供可用性區域。 腳本會設定訂閱,取得快照資源 ID,並從快照建立同一位置的管理磁碟。
#Provide the subscription Id of the subscription where you want to create Managed Disks
subscriptionId="<subscriptionId>"
#Provide the name of your resource group
resourceGroupName=myResourceGroupName
#Provide the name of the snapshot that will be used to create Managed Disks
snapshotName=mySnapshotName
#Provide the name of the new Managed Disks that will be create
diskName=myDiskName
#Provide the size of the disks in GB. It should be greater than the VHD file size.
diskSize=128
#Provide the storage type for Managed Disk. Acceptable values are Standard_LRS, Premium_LRS, PremiumV2_LRS, StandardSSD_LRS, UltraSSD_LRS, Premium_ZRS, and StandardSSD_ZRS.
storageType=Premium_LRS
#Required for Premium SSD v2 and Ultra Disks
#Provide the Availability Zone you'd like the disk to be created in, default is 1
zone=1
#Set the context to the subscription Id where Managed Disk will be created
az account set --subscription $subscriptionId
#Get the snapshot Id
snapshotId=$(az snapshot show --name $snapshotName --resource-group $resourceGroupName --query [id] -o tsv)
#Create a new Managed Disks using the snapshot Id
#Note that managed disk will be created in the same location as the snapshot
#If you're creating a Premium SSD v2 or an Ultra Disk, add "--zone $zone" to the end of the command
az disk create --resource-group $resourceGroupName --name $diskName --sku $storageType --size-gb $diskSize --source $snapshotId
具有客戶自控金鑰的磁碟
使用此腳本建立一個由客戶管理的金鑰管理的磁碟。 除了訂閱、資源群組、快照及新磁碟值外,還提供目標磁碟加密組及其資源群組。 腳本取得快照與磁碟加密集資訊,然後從快照建立指定磁碟加密設定的管理磁碟。
#Provide the subscription Id of the subscription where you want to create managed disks
subscriptionId="<subscriptionId>"
#Provide the name of your resource group
resourceGroupName=myResourceGroupName
#Provide the name of the snapshot that will be used to create managed disks
snapshotName=mySnapshotName
#Provide the name of the new managed disks that will be create
diskName=myDiskName
#Provide the name of the target disk encryption set
diskEncryptionSetName=myName
#Provide the target disk encryption set resource group
diskEncryptionResourceGroup=myGroup
#Required for Premium SSD v2 and Ultra Disks
#Provide the Availability Zone you'd like the disk to be created in, default is 1
zone=1
#Set the context to the subscription Id where managed disk will be created
az account set --subscription $subscriptionId
#Get the snapshot ID
snapshotId=$(az snapshot show --name $snapshotName --resource-group $resourceGroupName --query [id] -o tsv)
#Get the disk encryption set ID
diskEncryptionSetId=$(az disk-encryption-set show --name $diskEncryptionSetName --resource-group $diskEncryptionResourceGroup --query [id] -o tsv)
#Create a new managed disk using the snapshot ID
#The managed disk is created in the same location as the snapshot
#If you're creating a Premium SSD v2 or an Ultra Disk, add "--zone $zone" to the end of the command
az disk create -g $resourceGroupName -n $diskName --source $snapshotId --disk-encryption-set $diskEncryptionSetId
效能影響 - 背景複製程序
當您從快照集建立受控磁碟時,會啟動背景複製程序。 您可以在此程序執行時將磁碟連結至 VM,但您將會遇到效能影響 (4k 磁碟遇到讀取影響、512e 遇到讀取和寫入影響),延遲較高、IOPS 和輸送量降低,直到背景複製完成為止。 對於超大磁碟和高級 SSD v2,請使用以下指令檢查該 completionPercent 屬性。 當值達到 100時,背景副本即告完成。
重要事項
若是 Ultra 磁碟儲存體和進階 SSD v2 以外的磁碟類型,您無法使用下列區段取得背景複製程序的狀態。 其他磁碟類型則一律 100% 報告。
subscriptionId=yourSubscriptionID
resourceGroupName=yourResourceGroupName
diskName=yourDiskName
az account set --subscription $subscriptionId
az disk show -n $diskName -g $resourceGroupName --query [completionPercent] -o tsv
清除資源
執行以下指令刪除資源群組及其所有資源。
az group delete --name myResourceGroupName
Azure CLI 命令參考
這些腳本會使用以下 Azure CLI 指令來建立受管理磁碟、監控背景複製流程,以及清理資源。
| Command | 注意 |
|---|---|
| az account set | 設定訂閱權,並建立管理磁碟。 |
| az snapshot show(顯示快照資訊) | 取得來源快照資源 ID。 |
| az disk-encryption-set show | 取得使用客戶管理金鑰之磁碟的目標磁碟加密集合資訊。 |
| az disk create | 從來源快照建立一個受管理磁碟。 |
| az disk show | 取得 Premium SSD v2 和 Ultra Disk 的背景複製完成百分比。 |
| az 群組刪除 | 刪除資源群組及其資源。 |
後續步驟
如需 Azure CLI 的詳細資訊,請參閱 Azure CLI 文件。
您可以在 Azure Linux VM 文件中找到更多虛擬機器和受控磁碟的 CLI 指令碼範例。