如何通过GitHub Actions将多容器Docker应用部署至Azure Web App
多容器Docker应用自动化部署到Azure Web App
核心思路
Azure Web App支持通过Docker Compose配置多容器部署,我们可以通过GitHub Actions实现从代码提交到云端部署的全自动化,完全规避手动操作。以下是适配你的场景的完整流程:
1. 调整Docker Compose配置适配Azure
Azure多容器部署有几个关键限制,需要修改你的配置(建议在仓库中新增azure-compose.yml作为云端专用配置):
- 仅对外暴露80/443端口,前端服务需映射到80
- 不能使用本地绑定卷,需改用Azure Files存储模型文件(或把模型打包到镜像)
- 服务间通过内部网络通信,无需对外暴露后端端口
适配后的配置示例:
version: '3.8' services: server-app: image: tensorflow/serving command: ["--model_config_file=/models/models.config"] volumes: - azure-models:/models/ networks: - app-network client-app: image: user1234/client-app:latest restart: unless-stopped ports: - "80:80" networks: - app-network volumes: azure-models: driver: azure_file driver_opts: share_name: models-share storage_account_name: <替换为你的Azure存储账户名> networks: app-network: driver: bridge
替代方案:如果不想用Azure Files,可把
./content目录的模型文件打包到自定义TensorFlow Serving镜像,编写Dockerfile后推送到镜像仓库,再修改server-app的image字段为你的自定义镜像地址。
2. 配置GitHub Secrets
在你的GitHub仓库设置中添加以下密钥:
AZURE_CREDENTIALS:Azure服务主体的认证JSON(用于Actions操作Azure资源)DOCKER_HUB_USERNAME:你的Docker Hub用户名DOCKER_HUB_TOKEN:Docker Hub的访问令牌
生成Azure服务主体的命令:
az ad sp create-for-rbac --name "github-actions-deploy" --role contributor --scopes /subscriptions/<你的订阅ID>/resourceGroups/<你的资源组名> --sdk-auth复制命令输出的JSON内容,作为
AZURE_CREDENTIALS的值。
3. 编写GitHub Actions工作流
创建.github/workflows/deploy.yml文件,实现自动构建镜像、推送、部署到Azure:
name: 自动化部署多容器应用到Azure Web App on: push: branches: [ main ] jobs: build-deploy: runs-on: ubuntu-latest steps: # 拉取代码 - name: 检出仓库代码 uses: actions/checkout@v4 # 登录Docker Hub并构建推送client-app镜像 - name: 登录Docker Hub uses: docker/login-action@v3 with: username: ${{ secrets.DOCKER_HUB_USERNAME }} password: ${{ secrets.DOCKER_HUB_TOKEN }} - name: 构建并推送client-app镜像 uses: docker/build-push-action@v5 with: context: ./client-app file: ./client-app/dockerfile push: true tags: user1234/client-app:latest # 登录Azure - name: 登录Azure账户 uses: azure/login@v2 with: creds: ${{ secrets.AZURE_CREDENTIALS }} # (可选)自动创建Azure存储账户和文件共享,并上传模型文件 - name: 创建Azure存储资源并上传模型 run: | # 创建存储账户(替换占位符为你的信息) az storage account create --name <你的存储账户名> --resource-group <你的资源组名> --location <区域,如eastus> --sku Standard_LRS # 创建文件共享 az storage share create --name models-share --account-name <你的存储账户名> # 上传本地content目录的模型文件 az storage file upload-batch --source ./content --destination models-share --account-name <你的存储账户名> # 部署到Azure Web App - name: 部署到Azure多容器Web App uses: azure/webapps-deploy@v2 with: app-name: <你的Web App名称> resource-group: <你的资源组名> compose-file: ./azure-compose.yml
4. 验证部署
提交代码到main分支后,GitHub Actions会自动触发流程:
- 构建并推送client-app镜像到Docker Hub
- 创建Azure存储资源(如果启用可选步骤)
- 将多容器配置部署到Azure Web App
部署完成后,访问Web App的默认域名即可看到应用运行。
内容的提问来源于stack exchange,提问作者malisokan
相关产品推荐
相关产品推荐

