Terraform部署Azure容器:自定义镜像构建及ACG使用方案咨询
针对Azure容器镜像构建与部署的Terraform解决方案
方案一:用Azure容器注册表(ACR)任务自动构建镜像
这是Azure原生的等效方案,无需本地Docker环境,直接通过Terraform配置ACR完成镜像构建与存储:
- 先配置Azure容器注册表资源:
resource "azurerm_container_registry" "acr" { name = "your-acr-name" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name sku = "Premium" # 构建任务需要Standard或Premium SKU admin_enabled = false }
- 添加ACR构建任务,直接从代码仓库拉取Dockerfile和待COPY文件,自动构建并推送至ACR:
resource "azurerm_container_registry_task" "image_build" { name = "build-your-image" container_registry_name = azurerm_container_registry.acr.name resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location source_trigger { name = "github-trigger" source_type = "Github" github { repository_url = "https://github.com/your-username/your-repo.git" branch = "main" trigger_events = ["commit"] } trigger_enabled = true } encoded_step = base64encode(<<EOF FROM ubuntu:latest COPY ./your-files /target/path # 其他Docker指令 EOF ) platform { os_type = "Linux" cpu = 1 } }
- 容器组直接引用ACR中的镜像:
resource "azurerm_container_group" "containers" { name = "xxx" location = xxx resource_group_name = xxx ip_address_type = "Public" os_type = "Linux" container { name = "xxx" image = "${azurerm_container_registry.acr.login_server}/your-image:latest" cpu = "1" memory = "1.5" } image_registry_credential { server = azurerm_container_registry.acr.login_server username = azurerm_container_registry.acr.admin_username password = azurerm_container_registry.acr.admin_password } }
方案二:结合kreuzwerker/docker provider与ACR自动推送
若更习惯本地构建流程,可继续用kreuzwerker/docker provider构建镜像,再自动推送到ACR:
- 配置Docker provider与ACR登录凭证:
provider "docker" { host = "unix:///var/run/docker.sock" } data "azurerm_container_registry_credentials" "acr_creds" { name = azurerm_container_registry.acr.name resource_group_name = azurerm_resource_group.example.name } resource "docker_registry_image" "your_image" { name = "${azurerm_container_registry.acr.login_server}/your-image:latest" build { context = "./path-to-your-dockerfile-and-files" dockerfile = "Dockerfile" } registry_auth { address = azurerm_container_registry.acr.login_server username = data.azurerm_container_registry_credentials.acr_creds.username password = data.azurerm_container_registry_credentials.acr_creds.passwords[0].value } }
- 容器组引用镜像时,直接使用
docker_registry_image.your_image.name作为image字段的值即可。
注意事项
- ACR的Basic SKU不支持构建任务,需使用Standard或Premium级别的SKU。
- 采用本地构建方案时,需确保Terraform运行环境有Docker daemon权限,且能正常访问目标ACR。
内容的提问来源于stack exchange,提问作者herrm
相关产品推荐
相关产品推荐

