You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Bicep配置AKS监控成本预设及数据收集规则关联?

问题诊断与修复方案

核心问题

现有配置存在3个关键疏漏:

  1. 数据流不匹配「日志和事件」预设:当前DCR包含了Microsoft-KubePodInventory(标准预设的指标数据流),导致成本预设无法切换;
  2. 未禁用指标收集:「日志和事件」预设不需要收集指标,需显式关闭;
  3. DCR关联命名可能冲突:现有关联名称ContainerInsightsExtension与扩展名称重复,可能导致关联失效。

修复步骤

1. 更新数据收集规则(DCR)

修改appInsights.bicep中的appInsights_dataCollection资源,仅保留「日志和事件」需要的数据流,并禁用指标收集:

resource appInsights_dataCollection 'Microsoft.Insights/dataCollectionRules@2022-06-01' = {
  properties: {
    dataSources: {
      extensions: [
        {
          streams: [
            'Microsoft-ContainerLogV2'
            'Microsoft-KubeEvents'
          ]
          extensionName: 'ContainerInsights'
          extensionSettings: {
            dataCollectionSettings: {
              interval: '5m'
              namespaceFilteringMode: 'Off'
              enableContainerLogV2: true
              // 禁用指标收集,匹配「日志和事件」预设
              metricEnabled: false
            }
          }
          name: 'ContainerInsightsExtension'
        }
      ]
    }
    destinations: {
      logAnalytics: [
        {
          workspaceResourceId: logAnalyticsId // 改用传入参数,避免硬编码错误
          name: 'ciworkspace'
        }
      ]
    }
    dataFlows: [
      {
        streams: [
          'Microsoft-ContainerLogV2'
          'Microsoft-KubeEvents'
        ]
        destinations: [
          'ciworkspace'
        ]
      }
    ]
  }
  location: loc
  kind: 'Linux'
  name: 'MSCI-${loc}-abc-aks-we-${env}'
}

2. 修正DCR关联命名

修改appInsights.bicep中的关联资源名称,避免与扩展名称冲突:

resource appInsights_dataCollectionRuleAssociations 'Microsoft.Insights/dataCollectionRuleAssociations@2022-06-01' = {
  name: 'aks-dcr-log-events-assoc'
  scope: managedCluster
  properties: {
    dataCollectionRuleId: appInsights_dataCollection.id
    description: 'AKS cluster association to use Logs & Events cost preset'
  }
}

3. 确保AKS已启用Container Insights

如果AKS创建时未启用监控,先通过CLI启用:

az aks enable-addons --name abc-aks-we-dev --resource-group aks-dev --addons monitoring

4. 完善流水线部署命令

在azure-pipelines.yml中补充完整的部署参数:

inlineScript: |
  az group create --name aks-dev --location westeurope

  az deployment group create \
    --resource-group aks-dev \
    --template-file main.bicep \
    --parameters prefix=abc env=dev loc=westeurope

验证

  1. 重新运行流水线;
  2. 进入AKS集群的「监控」页面,确认成本预设已切换为「日志和事件」;
  3. 检查数据收集规则关联状态,确认AKS与目标DCR已绑定;
  4. 查看Log Analytics工作区,确认仅收集容器日志和Kubernetes事件。

内容的提问来源于stack exchange,提问作者NetDev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 06:25:55