將資料 API 建立器部署到 Azure Kubernetes Service

本指南將示範如何使用自訂容器映像推送到 Azure Container Registry,將 Data API 建構器(DAB)部署到 Azure Kubernetes Service (AKS)。 AKS 提供託管的 Kubernetes,擁有內建的擴展能力、監控探針和憑證管理。

部署至Azure Kubernetes Service後整體架構的示意圖已完成。

先決條件

建置組態檔

  1. 為你的設定檔建立一個本地目錄。

  2. 使用dab init初始化基礎設定檔。 使用 @env() 連接字串函式,讓秘密在執行時注入,而非直接內建到映像中。

    dab init \
      --database-type mssql \
      --connection-string "@env('DATABASE_CONNECTION_STRING')"
    
  3. 請至少加入一個實體,使用dab add。 對你想展示的每個表格或視圖重複這個步驟。

    dab add Books \
      --source dbo.Books \
      --permissions "anonymous:read"
    
  4. 繼續前先檢視 dab-config.json 一下。

建立並推送自訂容器映像檔

建立在 dab-config.json 中包含 /App/dab-config.json 的映像檔。

  1. 如果你還沒有 Azure 容器登錄檔,請建立一個。

    az acr create \
      --resource-group <resource-group> \
      --name <registry-name> \
      --sku Basic \
      --admin-enabled true
    
  2. 在與Dockerfile相同的目錄中建立dab-config.json。

    FROM mcr.microsoft.com/azure-databases/data-api-builder:latest
    COPY dab-config.json /App/dab-config.json
    
  3. 使用 ACR 任務建立並推送映像檔。

    az acr build \
      --registry <registry-name> \
      --image dab:latest \
      .
    
  4. 請注意完整圖片參考: <registry-name>.azurecr.io/dab:latest。

將 AKS 連接到 ACR

授權你的 AKS 叢集拉取登錄檔。

az aks update \
  --name <cluster-name> \
  --resource-group <resource-group> \
  --attach-acr <registry-name>

將連接字串儲存為 Kubernetes 秘密

把資料庫連線字串存成 Kubernetes 的秘密,這樣它就不會出現在 manifest 檔案裡。

kubectl create secret generic dab-secrets \
  --from-literal=DATABASE_CONNECTION_STRING="<your-connection-string>"

警告

切勿直接將連線字串放入 Kubernetes 清單檔案或容器映像檔中。 使用密鑰或 Azure Key Vault。

建立 Kubernetes 配置文件

建立具有下列內容的檔案 dab-deployment.yaml 。 請用你的 ACR 名稱來取代 <registry-name> 。

apiVersion: apps/v1
kind: Deployment
metadata:
  name: dab
  labels:
    app: dab
spec:
  replicas: 2
  selector:
    matchLabels:
      app: dab
  template:
    metadata:
      labels:
        app: dab
    spec:
      containers:
        - name: dab
          image: <registry-name>.azurecr.io/dab:latest
          ports:
            - containerPort: 5000
          env:
            - name: DATABASE_CONNECTION_STRING
              valueFrom:
                secretKeyRef:
                  name: dab-secrets
                  key: DATABASE_CONNECTION_STRING
          readinessProbe:
            httpGet:
              path: /health
              port: 5000
            initialDelaySeconds: 5
            periodSeconds: 10
          livenessProbe:
            httpGet:
              path: /health
              port: 5000
            initialDelaySeconds: 15
            periodSeconds: 20
---
apiVersion: v1
kind: Service
metadata:
  name: dab-service
spec:
  selector:
    app: dab
  ports:
    - protocol: TCP
      port: 80
      targetPort: 5000
  type: LoadBalancer

備註

readinessProbe 和 livenessProbe 使用 DAB /health 端點。 欲了解更多資訊,請參閱健康檢查。

部署到 AKS

  1. 取得叢集的認證憑證。

    az aks get-credentials \
      --resource-group <resource-group> \
      --name <cluster-name>
    
  2. 套用清單文件。

    kubectl apply -f dab-deployment.yaml
    
  3. 觀察部署過程直到艙體準備好。

    kubectl rollout status deployment/dab
    
  4. 取得分配給服務的外部 IP 位址。

    kubectl get service dab-service
    

    欄位 EXTERNAL-IP 顯示的是公共 IP 位址。 給負載平衡器預留一分鐘來配置。

驗證部署

  1. 瀏覽至 http://<external-ip>/health。 健康的回應應該是:

    {
      "status": "healthy",
      "version": "2.0.0",
      "app-name": "dab_oss_2.0.0"
    }
    
  2. 測試一個實體端點。

    curl http://<external-ip>/api/Books
    

調整部署規模

將複本數量改成橫向縮放。

kubectl scale deployment/dab --replicas=4

或者在 spec.replicas 中更新 dab-deployment.yaml 然後重新申請。

清理資源

當不再需要時,移除部署和服務。

kubectl delete -f dab-deployment.yaml
kubectl delete secret dab-secrets

要刪除 AKS 叢集和登錄檔,請移除資源群組。

az group delete \
  --name <resource-group> \
  --yes --no-wait