You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure App Configuration与AKS同步耗尽免费配额,求UI友好解决方案

AKS与Azure App Configuration配置同步的配额优化方案需求

环境与架构

  • 已部署AKS、Azure App Configuration(AAC)、Key Vault
  • AAC存储BgTaskTimer=10这类普通配置;Key Vault中的DbConnectionString以密钥保管库引用形式存入AAC
  • AKS中运行.NET控制台应用Pod,通过Azure App Configuration Kubernetes Provider关联AAC,采用工作负载身份认证

核心配置文件

main-api-deployment.yaml

---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: main-api
  namespace: dev
  labels:
    app: main-api
  annotations:
    reloader.stakater.com/auto: "true"
spec:
  replicas: 1
  selector:
    matchLabels:
      app: main-api
  template:
    metadata:
      labels:
        app: main-api
    spec:
      imagePullSecrets:
        - name: main-api-secret
      containers:
      - name: main-api
        image: my.azurecr.io/main-api:latest
        ports:
        - containerPort: 8080
        volumeMounts:
        - name: config-volume
          mountPath: /app/config
        - name: secret-volume
          mountPath: /app/secrets
      volumes:
      - name: config-volume 
        configMap: 
          name: configmap-created-by-appconfig-provider
      - name: secret-volume
        secret:
          secretName: secret-created-by-appconfig-provider

aac-provider.yaml

apiVersion: azconfig.io/v1
kind: AzureAppConfigurationProvider
metadata:
  name: appconfigurationprovider-sample
  namespace: dev
spec:
  endpoint: https://my.azconfig.io
  # AAC Values
  target:
    configMapName: configmap-created-by-appconfig-provider
    configMapData:
      type: json
      key: mysettings.json
  auth:
    workloadIdentity:
      serviceAccountName: appconfig-sa
  configuration:
    refresh:
      enabled: true
      interval: 30s
      monitoring:
        keyValues:
          - key: SentinelKey
  # Key Vault References
  secret:
    target:
      secretName: secret-created-by-appconfig-provider
      secretData:
        type: json
        key: mysettings.json
    auth:
      workloadIdentity:
        serviceAccountName: appconfig-sa
    refresh:
      enabled: false

配置读取代码

builder.Configuration.AddJsonFile("config/mysettings.json", reloadOnChange: true, optional: false);
builder.Configuration.AddJsonFile("secrets/mysettings.json", reloadOnChange: true, optional: false);

当前状态与问题

  • 现有功能正常:修改AAC中BgTaskTimer为60后,更新SentinelKey,Reloader会触发Pod滚动重启,应用能获取新值
  • 核心问题:30秒的刷新间隔会快速耗尽AAC免费层每日1000次请求配额,触发“请求过多”错误

已尝试的方案(均不满足需求)

  • 将刷新间隔改为15分钟:测试团队无法快速看到配置变更效果,不符合此前Web App修改后重启即生效的体验
  • 修改AAC配置后,通过修改YAML注释重新部署触发刷新:操作不够UI友好
  • Azure Event Grid + Azure Function方案:实现复杂度太高

额外背景

此前使用AKS + Key Vault CSI驱动实现自动变更检测时未出现配额问题,但因需要存储BgTaskTimer这类简单环境变量,选择AAC作为统一配置方案

需求

寻求UI友好的方案,实现AAC到AKS Pod的配置同步,同时不耗尽AAC免费层配额;若没有合适方案,只能让测试团队使用kubectl操作

内容的提问来源于stack exchange,提问作者Mihai Socaciu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 13:25:03