如何更新Azure ML现有AKS计算目标的过期自定义SSL证书?
更新Azure ML关联的AKS计算目标SSL证书(无需解绑重关联)
你可以直接通过Azure Machine Learning Python SDK对已关联的AKS计算目标执行证书更新操作,无需先解绑再重新关联,具体步骤如下:
- 加载现有AKS计算目标
先从工作区中获取已关联的AKS目标对象:
from azureml.core import Workspace, ComputeTarget # 加载工作区(根据实际认证方式调整,比如用config.json或服务主体) ws = Workspace.from_config() cluster_name = "你的AKS集群名称" aks_target = ComputeTarget(workspace=ws, name=cluster_name)
- 构建新的SSL配置并执行更新
使用新的PEM证书文件,通过update方法替换原有证书:
from azureml.core.compute.aks import AksUpdateConfiguration # 构建SSL更新配置,传入新的证书文件路径 ssl_update_config = AksUpdateConfiguration(ssl_cert_pem_file="新的mlsite_mycompany_com.pem", ssl_key_pem_file="新的private.pem", ssl_cname="mlsite.mycompany.com") # 执行更新操作 aks_target.update(update_config=ssl_update_config) aks_target.wait_for_completion(show_output=True)
注意事项
- 确保新证书是完整的PEM格式,包含服务器证书、中间证书链(如有),顺序需正确(服务器证书在前,中间CA证书在后)
- 私钥文件不能设置密码保护,否则更新操作会失败
- 更新过程中,AKS集群上的ML服务可能会出现短暂中断,建议在业务低峰时段执行操作
内容的提问来源于stack exchange,提问作者JakeUT
相关产品推荐
相关产品推荐

