在 Azure Red Hat OpenShift 4 上建立 Azure 檔案儲存體 儲存類別

在本文中,你要為 Azure Red Hat OpenShift 4 建立一個儲存類別,並透過 Azure 檔案儲存體 動態配置儲存空間。 您將瞭解如何:

  • 設置先決條件並安裝必要的工具
  • 使用 Azure 檔案儲存體 佈建器建立 Azure Red Hat OpenShift 4 儲存類別

如果你選擇在本地安裝並使用 CLI,這個教學需要 Azure CLI 2.6.0 或更新版本。 若要尋找版本,請執行 az --version 命令。 如果您需要安裝或升級,請參閱 安裝 Azure CLI。

開始之前

將 Azure Red Hat OpenShift 4 叢集部署到你的訂閱中。 欲了解更多資訊,請參閱「建立 Azure Red Hat OpenShift 4 叢集」。

設定一個 Azure 儲存帳號

此步驟會在 Azure Red Hat OpenShift 叢集的資源群組外建立一個資源群組。 此資源群組包含創建 Azure Red Hat OpenShift 動態配置器的 Azure 檔案儲存體 共享。

AZURE_FILES_RESOURCE_GROUP=aro_azure_files
LOCATION=eastus

az group create -l $LOCATION -n $AZURE_FILES_RESOURCE_GROUP

AZURE_STORAGE_ACCOUNT_NAME=aroazurefilessa

az storage account create \
  --name $AZURE_STORAGE_ACCOUNT_NAME \
  --resource-group $AZURE_FILES_RESOURCE_GROUP \
  --kind StorageV2 \
  --sku Standard_LRS

設定權限

設定資源群組權限和叢集權限。

對於資源群組權限,服務主體需要在新的 Azure 儲存帳號資源群組上取得listKeys權限。 指定貢獻者角色。

ARO_RESOURCE_GROUP=aro-rg
CLUSTER=cluster
ARO_SERVICE_PRINCIPAL_ID=$(az aro show -g $ARO_RESOURCE_GROUP -n $CLUSTER --query servicePrincipalProfile.clientId -o tsv)

az role assignment create --role Contributor --scope /subscriptions/mySubscriptionID/resourceGroups/$AZURE_FILES_RESOURCE_GROUP --assignee $ARO_SERVICE_PRINCIPAL_ID

就叢集權限而言,持久性磁碟區繫結器服務帳號必須具備讀取秘密物件的權限。 在 Azure Red Hat OpenShift 中建立並指派一個叢集角色。

ARO_API_SERVER=$(az aro list --query "[?contains(name,'$CLUSTER')].[apiserverProfile.url]" -o tsv)

oc login -u kubeadmin -p $(az aro list-credentials -g $ARO_RESOURCE_GROUP -n $CLUSTER --query=kubeadminPassword -o tsv) $ARO_API_SERVER

oc create clusterrole azure-secret-reader \
  --verb=create,get \
  --resource=secrets

oc adm policy add-cluster-role-to-user azure-secret-reader system:serviceaccount:kube-system:persistent-volume-binder

使用 Azure 檔案儲存體 佈建程式建立儲存體類別

此步驟會建立一個帶有 Azure 檔案儲存體 provisioner 的儲存類別。 你必須在儲存類別清單中包含儲存帳戶的詳細資料。 有了這些細節,叢集知道要查看目前資源群組外的儲存帳號。

在儲存佈建期間,secretName 規格會指定用於掛載的憑證所使用的密鑰。 在多租戶情境中,明確設定參數值 secretNamespace 。 否則,其他使用者可能會讀取儲存帳號的憑證。

cat << EOF >> azure-storageclass-azure-file.yaml
kind: StorageClass
apiVersion: storage.k8s.io/v1
metadata:
  name: azure-file
provisioner: file.csi.azure.com
mountOptions:
  - dir_mode=0777
  - file_mode=0777
  - uid=0
  - gid=0
  - mfsymlinks
  - cache=strict
  - actimeo=30
  - noperm
parameters:
  location: $LOCATION
  secretNamespace: kube-system
  skuName: Standard_LRS
  storageAccount: $AZURE_STORAGE_ACCOUNT_NAME
  resourceGroup: $AZURE_FILES_RESOURCE_GROUP
reclaimPolicy: Delete
volumeBindingMode: Immediate
EOF

oc create -f azure-storageclass-azure-file.yaml

Azure 檔案儲存體 的掛載選項通常取決於你部署的工作負載和應用程式的需求。 針對 Azure 檔案儲存體,考慮使用其他參數。

必要參數:

  • mfsymlinks 以映射 symlinks 到客戶端可用的表單。

  • noperm 以禁用用戶端的權限檢查。

建議參數:

  • nossharesock 如果用戶端已經透過現有掛載點連接,則關閉重複使用插槽的功能。

  • actimeo=30 (或更高)以延長通用網際網路檔案系統(CIFS)用戶端快取檔案與目錄屬性的時間。

  • nobrl 關閉向伺服器傳送位元組範圍鎖定請求。 此參數也建議用於在 Unix 可攜式作業系統介面(POSIX)中遇到鎖定問題的應用程式。

更改預設儲存類別(可選)

預設的儲存類別名為 managed premium,並使用 azure-disk 佈建程式。 透過針對儲存類別清單發出補丁指令來更改此設定。

oc patch storageclass managed-premium -p '{"metadata": {"annotations":{"storageclass.kubernetes.io/is-default-class":"false"}}}'

oc patch storageclass azure-file -p '{"metadata": {"annotations":{"storageclass.kubernetes.io/is-default-class":"true"}}}'

驗證 Azure 檔案儲存體 儲存體類別(可選)

建立新的應用程式,並向其指派儲存體。

備註

若要使用 httpd-example 範本,您必須在部署叢集時啟用提取密碼。 如需詳細資訊,請參閱取得 Red Hat pull secret。

oc new-project azfiletest
oc new-app httpd-example

#Wait for the pod to become Ready
curl $(oc get route httpd-example -n azfiletest -o jsonpath={.spec.host})

#If you have set the storage class by default, you can omit the --claim-class parameter
oc set volume dc/httpd-example --add --name=v1 -t pvc --claim-size=1G -m /data --claim-class='azure-file'

#Wait for the new deployment to rollout
export POD=$(oc get pods --field-selector=status.phase==Running -o jsonpath={.items[].metadata.name})
oc exec $POD -- bash -c "echo 'azure file storage' >> /data/test.txt"

oc exec $POD -- bash -c "cat /data/test.txt"
azure file storage

你可以透過Azure入口網站的儲存體總管看到 test.txt 檔案。