本指南將示範如何使用自訂容器映像推送到 Azure Container Registry,將 Data API 建構器(DAB)部署到 Azure Kubernetes Service (AKS)。 AKS 提供託管的 Kubernetes,擁有內建的擴展能力、監控探針和憑證管理。
先決條件
- 一個有有效訂閱的 Azure 帳號。 免費建立帳戶。
- 已安裝 Azure CLI
- Kubectl 安裝
- Docker 已 安裝
- 數據 API 產生器 CLI。 安裝 CLI
- 現有的 AKS 叢集。 建立 AKS 叢集
- 一個可由 AKS 存取的現有支援資料庫
建置組態檔
為你的設定檔建立一個本地目錄。
使用
dab init初始化基礎設定檔。 使用@env()連接字串函式,讓秘密在執行時注入,而非直接內建到映像中。dab init \ --database-type mssql \ --connection-string "@env('DATABASE_CONNECTION_STRING')"請至少加入一個實體,使用
dab add。 對你想展示的每個表格或視圖重複這個步驟。dab add Books \ --source dbo.Books \ --permissions "anonymous:read"繼續前先檢視
dab-config.json一下。
建立並推送自訂容器映像檔
建立在 dab-config.json 中包含 /App/dab-config.json 的映像檔。
如果你還沒有 Azure 容器登錄檔,請建立一個。
az acr create \ --resource-group <resource-group> \ --name <registry-name> \ --sku Basic \ --admin-enabled true在與
Dockerfile相同的目錄中建立dab-config.json。FROM mcr.microsoft.com/azure-databases/data-api-builder:latest COPY dab-config.json /App/dab-config.json使用 ACR 任務建立並推送映像檔。
az acr build \ --registry <registry-name> \ --image dab:latest \ .請注意完整圖片參考:
<registry-name>.azurecr.io/dab:latest。
將 AKS 連接到 ACR
授權你的 AKS 叢集拉取登錄檔。
az aks update \
--name <cluster-name> \
--resource-group <resource-group> \
--attach-acr <registry-name>
將連接字串儲存為 Kubernetes 秘密
把資料庫連線字串存成 Kubernetes 的秘密,這樣它就不會出現在 manifest 檔案裡。
kubectl create secret generic dab-secrets \
--from-literal=DATABASE_CONNECTION_STRING="<your-connection-string>"
警告
切勿直接將連線字串放入 Kubernetes 清單檔案或容器映像檔中。 使用密鑰或 Azure Key Vault。
建立 Kubernetes 配置文件
建立具有下列內容的檔案 dab-deployment.yaml 。 請用你的 ACR 名稱來取代 <registry-name> 。
apiVersion: apps/v1
kind: Deployment
metadata:
name: dab
labels:
app: dab
spec:
replicas: 2
selector:
matchLabels:
app: dab
template:
metadata:
labels:
app: dab
spec:
containers:
- name: dab
image: <registry-name>.azurecr.io/dab:latest
ports:
- containerPort: 5000
env:
- name: DATABASE_CONNECTION_STRING
valueFrom:
secretKeyRef:
name: dab-secrets
key: DATABASE_CONNECTION_STRING
readinessProbe:
httpGet:
path: /health
port: 5000
initialDelaySeconds: 5
periodSeconds: 10
livenessProbe:
httpGet:
path: /health
port: 5000
initialDelaySeconds: 15
periodSeconds: 20
---
apiVersion: v1
kind: Service
metadata:
name: dab-service
spec:
selector:
app: dab
ports:
- protocol: TCP
port: 80
targetPort: 5000
type: LoadBalancer
備註
readinessProbe 和 livenessProbe 使用 DAB /health 端點。 欲了解更多資訊,請參閱健康檢查。
部署到 AKS
取得叢集的認證憑證。
az aks get-credentials \ --resource-group <resource-group> \ --name <cluster-name>套用清單文件。
kubectl apply -f dab-deployment.yaml觀察部署過程直到艙體準備好。
kubectl rollout status deployment/dab取得分配給服務的外部 IP 位址。
kubectl get service dab-service欄位
EXTERNAL-IP顯示的是公共 IP 位址。 給負載平衡器預留一分鐘來配置。
驗證部署
瀏覽至
http://<external-ip>/health。 健康的回應應該是:{ "status": "healthy", "version": "2.0.0", "app-name": "dab_oss_2.0.0" }測試一個實體端點。
curl http://<external-ip>/api/Books
調整部署規模
將複本數量改成橫向縮放。
kubectl scale deployment/dab --replicas=4
或者在 spec.replicas 中更新 dab-deployment.yaml 然後重新申請。
清理資源
當不再需要時,移除部署和服務。
kubectl delete -f dab-deployment.yaml
kubectl delete secret dab-secrets
要刪除 AKS 叢集和登錄檔,請移除資源群組。
az group delete \
--name <resource-group> \
--yes --no-wait
相關內容
- 部署至 Azure 容器應用程式
- 部署至 Azure 容器實例
- 部署選項概述
- 健康檢查
- 部署最佳實務:安全性