From 01386f7790ae2baba366b970ac58a46e79bc2fa3 Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Wed, 12 Aug 2020 23:59:17 +0100 Subject: [PATCH 01/16] add bdc private cluster sample --- .../private-bdc/ARMtemplates/parameters.json | 21 + .../private-bdc/ARMtemplates/template.json | 367 ++++++++++++++++++ .../private-bdc/README.md | 2 + .../scripts/deploy-private-aks-udr.sh | 116 ++++++ .../private-bdc/scripts/deploy-private-aks.sh | 40 ++ .../private-bdc/scripts/deploy-private-bdc.sh | 24 ++ 6 files changed, 570 insertions(+) create mode 100644 samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/parameters.json create mode 100644 samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json create mode 100644 samples/features/sql-big-data-cluster/private-bdc/README.md create mode 100644 samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks-udr.sh create mode 100644 samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks.sh create mode 100644 samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-bdc.sh diff --git a/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/parameters.json b/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/parameters.json new file mode 100644 index 00000000..bb613613 --- /dev/null +++ b/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/parameters.json @@ -0,0 +1,21 @@ +{ + "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#", + "contentVersion": "1.0.0.0", + "parameters": { + "routeTables_bdcaks_rt_name": { + "value": null + }, + "virtualNetworks_bdc_vnet_name": { + "value": null + }, + "azureFirewalls_bdcaksazfw_name": { + "value": null + }, + "publicIPAddresses_bdcaksazfw_ip_name": { + "value": null + }, + "managedClusters_bdcaksprivatecluster_name": { + "value": null + } + } +} \ No newline at end of file diff --git a/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json b/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json new file mode 100644 index 00000000..8b208b3c --- /dev/null +++ b/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json @@ -0,0 +1,367 @@ +{ + "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#", + "contentVersion": "1.0.0.0", + "parameters": { + "routeTables_bdcaks_rt_name": { + "defaultValue": "bdcaks-rt", + "type": "String" + }, + "virtualNetworks_bdc_vnet_name": { + "defaultValue": "bdc-vnet", + "type": "String" + }, + "azureFirewalls_bdcaksazfw_name": { + "defaultValue": "bdcaksazfw", + "type": "String" + }, + "publicIPAddresses_bdcaksazfw_ip_name": { + "defaultValue": "bdcaksazfw-ip", + "type": "String" + }, + "managedClusters_bdcaksprivatecluster_name": { + "defaultValue": "bdcaksprivatecluster", + "type": "String" + } + }, + "variables": {}, + "resources": [ + { + "type": "Microsoft.Network/publicIPAddresses", + "apiVersion": "2020-05-01", + "name": "[parameters('publicIPAddresses_bdcaksazfw_ip_name')]", + "location": "northeurope", + "sku": { + "name": "Standard" + }, + "properties": { + "ipAddress": "51.104.159.190", + "publicIPAddressVersion": "IPv4", + "publicIPAllocationMethod": "Static", + "idleTimeoutInMinutes": 4, + "ipTags": [] + } + }, + { + "type": "Microsoft.Network/routeTables", + "apiVersion": "2020-05-01", + "name": "[parameters('routeTables_bdcaks_rt_name')]", + "location": "northeurope", + "properties": { + "disableBgpRoutePropagation": false, + "routes": [ + { + "name": "bdcaksrouteinet", + "properties": { + "addressPrefix": "51.104.159.190/32", + "nextHopType": "Internet" + } + }, + { + "name": "bdcaksroute", + "properties": { + "addressPrefix": "0.0.0.0/0", + "nextHopType": "VirtualAppliance", + "nextHopIpAddress": "10.2.0.4" + } + } + ] + } + }, + { + "type": "Microsoft.ContainerService/managedClusters", + "apiVersion": "2020-06-01", + "name": "[parameters('managedClusters_bdcaksprivatecluster_name')]", + "location": "northeurope", + "dependsOn": [ + "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'aks-subnet')]" + ], + "sku": { + "name": "Basic", + "tier": "Free" + }, + "properties": { + "kubernetesVersion": "1.16.13", + "dnsPrefix": "bdcakspriv-private-bdc-rg-a00fa0", + "agentPoolProfiles": [ + { + "name": "nodepool1", + "count": 2, + "vmSize": "Standard_D13_v2", + "osDiskSizeGB": 128, + "vnetSubnetID": "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'aks-subnet')]", + "maxPods": 30, + "type": "VirtualMachineScaleSets", + "orchestratorVersion": "1.16.13", + "enableNodePublicIP": false, + "nodeLabels": {}, + "mode": "System", + "osType": "Linux", + "nodeImageVersion": "AKSUbuntu-1604-2020.07.16" + } + ], + "linuxProfile": { + "adminUsername": "azureuser", + "ssh": { + "publicKeys": [ + { + "keyData": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC+2Ev5GnLtDTsb/xnYFVFqyJejTQy+tH9Z5jhh4h+h1zDLZESubjzKkSIcBaUq1BDypC2HWY3GojxOW8QSKtlxdZNMBoX2/POsc+XeU/iPPYi243wMCBKOyIS5iLrT+86sDCDSVScmaFiA7fGSQOp3ghYY+517s1yWFWdbbChVP0OWjPDa8CeiMPDJFraT5stcFuEJ/ef1qidz48bvJJJKiKQ+7VS4VjqKFsM+n7uvKC0V5hZZ6WH7Ld5q1zR4OImySiYHRzNob6Q9f14MOTCu+JLbdONZLRAR83daw30fCL2V8NGqSVFAA/oRwarZpCZvrNJSCUUc6esDax36pEjx" + } + ] + } + }, + "windowsProfile": { + "adminUsername": "azureuser" + }, + "servicePrincipalProfile": { + "clientId": "17915f2a-09da-4729-8f62-c7121f28a4f2" + }, + "addonProfiles": { + "KubeDashboard": { + "enabled": true + } + }, + "nodeResourceGroup": "[concat('MC_private-bdc-rg_', parameters('managedClusters_bdcaksprivatecluster_name'), '_northeurope')]", + "enableRBAC": true, + "networkProfile": { + "networkPlugin": "azure", + "loadBalancerSku": "Standard", + "serviceCidr": "10.3.0.0/24", + "dnsServiceIP": "10.3.0.10", + "dockerBridgeCidr": "172.17.0.1/16", + "outboundType": "userDefinedRouting" + }, + "apiServerAccessProfile": { + "enablePrivateCluster": true + } + } + }, + { + "type": "Microsoft.Network/routeTables/routes", + "apiVersion": "2020-05-01", + "name": "[concat(parameters('routeTables_bdcaks_rt_name'), '/bdcaksroute')]", + "dependsOn": [ + "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" + ], + "properties": { + "addressPrefix": "0.0.0.0/0", + "nextHopType": "VirtualAppliance", + "nextHopIpAddress": "10.2.0.4" + } + }, + { + "type": "Microsoft.Network/routeTables/routes", + "apiVersion": "2020-05-01", + "name": "[concat(parameters('routeTables_bdcaks_rt_name'), '/bdcaksrouteinet')]", + "dependsOn": [ + "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" + ], + "properties": { + "addressPrefix": "51.104.159.190/32", + "nextHopType": "Internet" + } + }, + { + "type": "Microsoft.Network/virtualNetworks", + "apiVersion": "2020-05-01", + "name": "[parameters('virtualNetworks_bdc_vnet_name')]", + "location": "northeurope", + "dependsOn": [ + "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" + ], + "properties": { + "addressSpace": { + "addressPrefixes": [ + "10.0.0.0/8" + ] + }, + "dhcpOptions": { + "dnsServers": [] + }, + "subnets": [ + { + "name": "AzureFirewallSubnet", + "properties": { + "addressPrefix": "10.2.0.0/24", + "delegations": [], + "privateEndpointNetworkPolicies": "Enabled", + "privateLinkServiceNetworkPolicies": "Enabled" + } + }, + { + "name": "aks-subnet", + "properties": { + "addressPrefix": "10.1.0.0/16", + "routeTable": { + "id": "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" + }, + "delegations": [], + "privateEndpointNetworkPolicies": "Disabled", + "privateLinkServiceNetworkPolicies": "Enabled" + } + } + ], + "virtualNetworkPeerings": [], + "enableDdosProtection": false, + "enableVmProtection": false + } + }, + { + "type": "Microsoft.Network/virtualNetworks/subnets", + "apiVersion": "2020-05-01", + "name": "[concat(parameters('virtualNetworks_bdc_vnet_name'), '/AzureFirewallSubnet')]", + "dependsOn": [ + "[resourceId('Microsoft.Network/virtualNetworks', parameters('virtualNetworks_bdc_vnet_name'))]" + ], + "properties": { + "addressPrefix": "10.2.0.0/24", + "delegations": [], + "privateEndpointNetworkPolicies": "Enabled", + "privateLinkServiceNetworkPolicies": "Enabled" + } + }, + { + "type": "Microsoft.ContainerService/managedClusters/agentPools", + "apiVersion": "2020-06-01", + "name": "[concat(parameters('managedClusters_bdcaksprivatecluster_name'), '/nodepool1')]", + "dependsOn": [ + "[resourceId('Microsoft.ContainerService/managedClusters', parameters('managedClusters_bdcaksprivatecluster_name'))]", + "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'aks-subnet')]" + ], + "properties": { + "count": 2, + "vmSize": "Standard_D13_v2", + "osDiskSizeGB": 128, + "vnetSubnetID": "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'aks-subnet')]", + "maxPods": 30, + "type": "VirtualMachineScaleSets", + "orchestratorVersion": "1.16.13", + "enableNodePublicIP": false, + "nodeLabels": {}, + "mode": "System", + "osType": "Linux", + "nodeImageVersion": "AKSUbuntu-1604-2020.07.16" + } + }, + { + "type": "Microsoft.Network/azureFirewalls", + "apiVersion": "2020-05-01", + "name": "[parameters('azureFirewalls_bdcaksazfw_name')]", + "location": "northeurope", + "dependsOn": [ + "[resourceId('Microsoft.Network/publicIPAddresses', parameters('publicIPAddresses_bdcaksazfw_ip_name'))]", + "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'AzureFirewallSubnet')]" + ], + "properties": { + "sku": { + "name": "AZFW_VNet", + "tier": "Standard" + }, + "threatIntelMode": "Alert", + "additionalProperties": { + "Network.DNS.EnableProxy": "True", + "Network.DNS.RequireProxyForNetworkRules": "True" + }, + "ipConfigurations": [ + { + "name": "[concat(parameters('azureFirewalls_bdcaksazfw_name'), '-config')]", + "properties": { + "publicIPAddress": { + "id": "[resourceId('Microsoft.Network/publicIPAddresses', parameters('publicIPAddresses_bdcaksazfw_ip_name'))]" + }, + "subnet": { + "id": "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'AzureFirewallSubnet')]" + } + } + } + ], + "networkRuleCollections": [ + { + "name": "aksfwnr", + "properties": { + "priority": 100, + "action": { + "type": "Allow" + }, + "rules": [ + { + "name": "apiudp", + "protocols": [ + "UDP" + ], + "sourceAddresses": [ + "*" + ], + "destinationAddresses": [ + "AzureCloud.northeurope" + ], + "sourceIpGroups": [], + "destinationIpGroups": [], + "destinationFqdns": [], + "destinationPorts": [ + "1194" + ] + }, + { + "name": "apitcp", + "protocols": [ + "TCP" + ], + "sourceAddresses": [ + "*" + ], + "destinationAddresses": [ + "AzureCloud.northeurope" + ], + "sourceIpGroups": [], + "destinationIpGroups": [], + "destinationFqdns": [], + "destinationPorts": [ + "9000" + ] + }, + { + "name": "time", + "protocols": [ + "UDP" + ], + "sourceAddresses": [ + "*" + ], + "destinationAddresses": [], + "sourceIpGroups": [], + "destinationIpGroups": [], + "destinationFqdns": [ + "ntp.ubuntu.com" + ], + "destinationPorts": [ + "123" + ] + } + ] + } + } + ], + "applicationRuleCollections": [], + "natRuleCollections": [] + } + }, + { + "type": "Microsoft.Network/virtualNetworks/subnets", + "apiVersion": "2020-05-01", + "name": "[concat(parameters('virtualNetworks_bdc_vnet_name'), '/aks-subnet')]", + "dependsOn": [ + "[resourceId('Microsoft.Network/virtualNetworks', parameters('virtualNetworks_bdc_vnet_name'))]", + "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" + ], + "properties": { + "addressPrefix": "10.1.0.0/16", + "routeTable": { + "id": "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" + }, + "delegations": [], + "privateEndpointNetworkPolicies": "Disabled", + "privateLinkServiceNetworkPolicies": "Enabled" + } + } + ] +} \ No newline at end of file diff --git a/samples/features/sql-big-data-cluster/private-bdc/README.md b/samples/features/sql-big-data-cluster/private-bdc/README.md new file mode 100644 index 00000000..692e1049 --- /dev/null +++ b/samples/features/sql-big-data-cluster/private-bdc/README.md @@ -0,0 +1,2 @@ +# Deploy BDC in private AKS cluster with User-defined Route (UDR) + diff --git a/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks-udr.sh new file mode 100644 index 00000000..5102fded --- /dev/null +++ b/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks-udr.sh @@ -0,0 +1,116 @@ +#!/bin/bash + +export SUBID= + +export REGION_NAME=northeurope +export RESOURCE_GROUP=private-bdc-rg +export SUBNET_NAME=aks-subnet +export VNET_NAME=bdc-vnet +export AKS_NAME=bdcaksprivatecluster +export FWNAME=bdcaksazfw +export FWPUBIP=$FWNAME-ip +export FWIPCONFIG_NAME=$FWNAME-config + +export FWROUTE_TABLE_NAME=bdcaks-rt +export FWROUTE_NAME=bdcaksroute +export FWROUTE_NAME_INTERNET=bdcaksrouteinet + + + +az group create -n $RESOURCE_GROUP -l $REGION_NAME + +az network vnet create \ + --resource-group $RESOURCE_GROUP \ + --location $REGION_NAME \ + --name $VNET_NAME \ + --address-prefixes 10.0.0.0/8 \ + --subnet-name $SUBNET_NAME \ + --subnet-prefix 10.1.0.0/16 + + +SUBNET_ID=$(az network vnet subnet show \ + --resource-group $RESOURCE_GROUP \ + --vnet-name $VNET_NAME \ + --name $SUBNET_NAME \ + --query id -o tsv) + + +az extension add --name azure-firewall + +# Dedicated subnet for Azure Firewall (Firewall name cannot be changed) + +az network vnet subnet create \ + --resource-group $RESOURCE_GROUP \ + --vnet-name $VNET_NAME \ + --name AzureFirewallSubnet \ + --address-prefix 10.2.0.0/24 + +az network firewall create -g $RESOURCE_GROUP -n $FWNAME -l $REGION_NAME --enable-dns-proxy true + +az network public-ip create -g $RESOURCE_GROUP -n $FWPUBIP -l $REGION_NAME --sku "Standard" + +az network firewall ip-config create -g $RESOURCE_GROUP -f $FWNAME -n $FWIPCONFIG_NAME --public-ip-address $FWPUBIP --vnet-name $VNET_NAME + + + +export FWPUBLIC_IP=$(az network public-ip show -g $RESOURCE_GROUP -n $FWPUBIP --query "ipAddress" -o tsv) +export FWPRIVATE_IP=$(az network firewall show -g $RESOURCE_GROUP -n $FWNAME --query "ipConfigurations[0].privateIpAddress" -o tsv) + +az network route-table create -g $RESOURCE_GROUP --name $FWROUTE_TABLE_NAME + +az network route-table route create -g $RESOURCE_GROUP --name $FWROUTE_NAME --route-table-name $FWROUTE_TABLE_NAME --address-prefix 0.0.0.0/0 --next-hop-type VirtualAppliance --next-hop-ip-address $FWPRIVATE_IP --subscription $SUBID + +az network route-table route create -g $RESOURCE_GROUP --name $FWROUTE_NAME_INTERNET --route-table-name $FWROUTE_TABLE_NAME --address-prefix $FWPUBLIC_IP/32 --next-hop-type Internet + + +# Add FW Network Rules + +az network firewall network-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwnr' -n 'apiudp' --protocols 'UDP' --source-addresses '*' --destination-addresses "AzureCloud.$REGION_NAME" --destination-ports 1194 --action allow --priority 100 +az network firewall network-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwnr' -n 'apitcp' --protocols 'TCP' --source-addresses '*' --destination-addresses "AzureCloud.$REGION_NAME" --destination-ports 9000 +az network firewall network-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwnr' -n 'time' --protocols 'UDP' --source-addresses '*' --destination-fqdns 'ntp.ubuntu.com' --destination-ports 123 + +# Add FW Application Rules + +az network firewall application-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwar' -n 'fqdn' --source-addresses '*' --protocols 'http=80' 'https=443' --fqdn-tags "AzureKubernetesService" --action allow --priority 100 + +# Associate User defined route table (UDR) to AKS cluster where deployed BDC previsouly +az network vnet subnet update -g $RESOURCE_GROUP --vnet-name $VNET_NAME --name $SUBNET_NAME --route-table $FWROUTE_TABLE_NAME + + + + + +# Create SP and Assign Permission to Virtual Network + +az ad sp create-for-rbac -n "bdcaks-sp" --skip-assignment + +export APPID= +export PASSWORD=< your service principle password > +export VNETID=$(az network vnet show -g $RESOURCE_GROUP --name $VNET_NAME --query id -o tsv) + +# Assign SP Permission to VNET + +az role assignment create --assignee $APPID --scope $VNETID --role "Network Contributor" + + +export RTID=$(az network route-table show -g $RESOURCE_GROUP -n $FWROUTE_TABLE_NAME --query id -o tsv) +az role assignment create --assignee $APPID --scope $RTID --role "Network Contributor" + + +az aks create \ + --resource-group $RESOURCE_GROUP \ + --location $REGION_NAME \ + --name $AKS_NAME \ + --load-balancer-sku standard \ + --outbound-type userDefinedRouting \ + --enable-private-cluster \ + --network-plugin azure \ + --vnet-subnet-id $SUBNET_ID \ + --docker-bridge-address 172.17.0.1/16 \ + --dns-service-ip 10.2.0.10 \ + --service-cidr 10.2.0.0/24 \ + --service-principal $APPID \ + --client-secret $PASSWORD \ + --node-vm-size Standard_D13_v2 \ + --node-count 2 \ + --generate-ssh-keys diff --git a/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks.sh b/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks.sh new file mode 100644 index 00000000..6ce64405 --- /dev/null +++ b/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks.sh @@ -0,0 +1,40 @@ +#!/bin/bash + +# Define a set of environment variables to be used in resource creations. + +export REGION_NAME=northeurope +export RESOURCE_GROUP=private-bdc-aks-rg +export SUBNET_NAME=aks-subnet +export VNET_NAME=bdc-vnet +export AKS_NAME=bdcaksprivatecluster + +az group create -n $RESOURCE_GROUP -l $REGION_NAME + +az network vnet create \ + --resource-group $RESOURCE_GROUP \ + --location $REGION_NAME \ + --name $VNET_NAME \ + --address-prefixes 10.0.0.0/8 \ + --subnet-name $SUBNET_NAME \ + --subnet-prefix 10.1.0.0/16 + + +SUBNET_ID=$(az network vnet subnet show \ + --resource-group $RESOURCE_GROUP \ + --vnet-name $VNET_NAME \ + --name $SUBNET_NAME \ + --query id -o tsv) + +az aks create \ + --resource-group $RESOURCE_GROUP \ + --name $AKS_NAME \ + --load-balancer-sku standard \ + --enable-private-cluster \ + --network-plugin azure \ + --vnet-subnet-id $SUBNET_ID \ + --docker-bridge-address 172.17.0.1/16 \ + --dns-service-ip 10.2.0.10 \ + --service-cidr 10.2.0.0/24 \ + --node-vm-size Standard_D13_v2 \ + --node-count 2 \ + --generate-ssh-keys diff --git a/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-bdc.sh b/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-bdc.sh new file mode 100644 index 00000000..f674b856 --- /dev/null +++ b/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-bdc.sh @@ -0,0 +1,24 @@ +#!/bin/bash + +azdata bdc config init --source aks-dev-test --target private-bdc-aks --force + +azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.docker.imageTag=2019-CU6-ubuntu-16.04" +azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.storage.data.className=default" +azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.storage.logs.className=default" + +azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.endpoints[0].serviceType=NodePort" +azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.endpoints[1].serviceType=NodePort" + +azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.master.spec.endpoints[0].serviceType=NodePort" +azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.gateway.spec.endpoints[0].serviceType=NodePort" +azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.appproxy.spec.endpoints[0].serviceType=NodePort" + +# In case you're deploying BDC in HA mode ( aks-dev-test-ha profile ) please also use the following command +# azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.master.spec.endpoints[1].serviceType= NodePort" + + +export AZDATA_USERNAME= +export AZDATA_PASSWORD=< your bdcadmin password> +export ACCEPT_EULA=yes #accept agreement + +azdata bdc create --config-profile private-bdc-aks --accept-eula yes From 31731966befa069d426ad309eccc2e9f8bc5680f Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Fri, 14 Aug 2020 00:08:28 +0100 Subject: [PATCH 02/16] update templates --- .../private-bdc/ARMtemplates/template.json | 464 ++++++++++-------- .../private-bdc/README.md | 8 + 2 files changed, 261 insertions(+), 211 deletions(-) diff --git a/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json b/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json index 8b208b3c..317f6d6b 100644 --- a/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json +++ b/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json @@ -2,34 +2,176 @@ "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { - "routeTables_bdcaks_rt_name": { + "aksclusterName": { + "type": "string", + "metadata": { + "description": "The name of the AKS Managed Cluster resource." + } + }, + "location": { + "type": "string", + "defaultValue": "[resourceGroup().location]", + "metadata": { + "description": "The Azure location of the AKS resource." + } + }, + "dnsPrefix": { + "type": "string", + "metadata": { + "description": "Optional DNS prefix to use with hosted Kubernetes API server FQDN." + } + }, + "agentCount": { + "defaultValue": 3, + "minValue": 1, + "maxValue": 50, + "type": "int", + "metadata": { + "description": "The number of agent nodes for the cluster. Production workloads have a recommended minimum of 3." + } + }, + "agentVMSize": { + "defaultValue": "Standard_D13_v2", + "type": "string", + "metadata": { + "description": "The recommended size of the Virtual Machine." + } + }, + "existingServicePrincipalObjectId": { + "type": "string", + "metadata": { + "description": "Object ID against which the Network Contributor roles will be assigned on the subnet" + } + }, + "existingServicePrincipalClientId": { + "type": "string", + "metadata": { + "description": "Client ID (used by cloudprovider)" + } + }, + "existingServicePrincipalClientSecret": { + "type": "securestring", + "metadata": { + "description": "The Service Principal Client Secret." + } + }, + "kubernetesVersion": { + "defaultValue": "1.16.13", + "type": "string", + "metadata": { + "description": "The version of Kubernetes." + } + }, + "serviceCidr": { + "type": "string", + "defaultValue": "10.3.0.0/24", + "metadata": { + "description": "A CIDR notation IP range from which to assign service cluster IPs." + } + }, + "dnsServiceIP": { + "type": "string", + "defaultValue": "10.3.0.10", + "metadata": { + "description": "Containers DNS server IP address." + } + }, + "dockerBridgeCidr": { + "type": "string", + "defaultValue": "172.17.0.1/16", + "metadata": { + "description": "A CIDR notation IP for Docker bridge." + } + }, + "routetableName": { "defaultValue": "bdcaks-rt", "type": "String" }, - "virtualNetworks_bdc_vnet_name": { - "defaultValue": "bdc-vnet", + "vnetName": { + "defaultValue": "bdcaks-vnet", "type": "String" }, - "azureFirewalls_bdcaksazfw_name": { + "subnetName": { + "defaultValue": "bdcaks-subnet", + "type": "String" + }, + "azureFirewallName": { "defaultValue": "bdcaksazfw", "type": "String" }, - "publicIPAddresses_bdcaksazfw_ip_name": { + "azureFirewallPublicIP": { "defaultValue": "bdcaksazfw-ip", "type": "String" - }, - "managedClusters_bdcaksprivatecluster_name": { - "defaultValue": "bdcaksprivatecluster", - "type": "String" - } + } + }, + "variables": { + "networkRoleDefinitionID":"[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Authorization/roleDefinitions/', '4d97b98b-1d4f-4787-a291-c67834d212e7')]", + "vnetSubnetID":"[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('vnetName'), parameters('subnetName'))]" }, - "variables": {}, "resources": [ + { + "type": "Microsoft.Network/virtualNetworks", + "apiVersion": "2020-05-01", + "name": "[parameters('vnetName')]", + "location": "[parameters('location')]", + "dependsOn": [ + "[resourceId('Microsoft.Network/routeTables', parameters('routetableName'))]" + ], + "properties": { + "addressSpace": { + "addressPrefixes": [ + "10.0.0.0/8" + ] + }, + "dhcpOptions": { + "dnsServers": [] + }, + "virtualNetworkPeerings": [], + "enableDdosProtection": false, + "enableVmProtection": false + }, + "resources": [ + { + "type": "subnets", + "apiVersion": "2020-05-01", + "location": "[parameters('location')]", + "name": "AzureFirewallSubnet", + "dependsOn": [ + "[resourceId('Microsoft.Network/virtualNetworks', parameters('vnetName'))]" + ], + "properties": { + "addressPrefix": "10.2.0.0/24", + "delegations": [], + "privateEndpointNetworkPolicies": "Enabled", + "privateLinkServiceNetworkPolicies": "Enabled" + } + }, + { + "type": "subnets", + "apiVersion": "2020-05-01", + "location": "[parameters('location')]", + "name": "[parameters('subnetName')]", + "dependsOn": [ + "[resourceId('Microsoft.Network/virtualNetworks', parameters('vnetName'))]", + "[resourceId('Microsoft.Network/routeTables', parameters('routetableName'))]" + ], + "properties": { + "addressPrefix": "10.1.0.0/16", + "routeTable": { + "id": "[resourceId('Microsoft.Network/routeTables', parameters('routetableName'))]" + }, + "delegations": [], + "privateEndpointNetworkPolicies": "Disabled", + "privateLinkServiceNetworkPolicies": "Enabled" + } + } + ] + }, { "type": "Microsoft.Network/publicIPAddresses", "apiVersion": "2020-05-01", - "name": "[parameters('publicIPAddresses_bdcaksazfw_ip_name')]", - "location": "northeurope", + "name": "[parameters('azureFirewallPublicIP')]", + "location": "[parameters('location')]", "sku": { "name": "Standard" }, @@ -44,8 +186,8 @@ { "type": "Microsoft.Network/routeTables", "apiVersion": "2020-05-01", - "name": "[parameters('routeTables_bdcaks_rt_name')]", - "location": "northeurope", + "name": "[parameters('routetableName')]", + "location": "[parameters('location')]", "properties": { "disableBgpRoutePropagation": false, "routes": [ @@ -67,189 +209,14 @@ ] } }, - { - "type": "Microsoft.ContainerService/managedClusters", - "apiVersion": "2020-06-01", - "name": "[parameters('managedClusters_bdcaksprivatecluster_name')]", - "location": "northeurope", - "dependsOn": [ - "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'aks-subnet')]" - ], - "sku": { - "name": "Basic", - "tier": "Free" - }, - "properties": { - "kubernetesVersion": "1.16.13", - "dnsPrefix": "bdcakspriv-private-bdc-rg-a00fa0", - "agentPoolProfiles": [ - { - "name": "nodepool1", - "count": 2, - "vmSize": "Standard_D13_v2", - "osDiskSizeGB": 128, - "vnetSubnetID": "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'aks-subnet')]", - "maxPods": 30, - "type": "VirtualMachineScaleSets", - "orchestratorVersion": "1.16.13", - "enableNodePublicIP": false, - "nodeLabels": {}, - "mode": "System", - "osType": "Linux", - "nodeImageVersion": "AKSUbuntu-1604-2020.07.16" - } - ], - "linuxProfile": { - "adminUsername": "azureuser", - "ssh": { - "publicKeys": [ - { - "keyData": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC+2Ev5GnLtDTsb/xnYFVFqyJejTQy+tH9Z5jhh4h+h1zDLZESubjzKkSIcBaUq1BDypC2HWY3GojxOW8QSKtlxdZNMBoX2/POsc+XeU/iPPYi243wMCBKOyIS5iLrT+86sDCDSVScmaFiA7fGSQOp3ghYY+517s1yWFWdbbChVP0OWjPDa8CeiMPDJFraT5stcFuEJ/ef1qidz48bvJJJKiKQ+7VS4VjqKFsM+n7uvKC0V5hZZ6WH7Ld5q1zR4OImySiYHRzNob6Q9f14MOTCu+JLbdONZLRAR83daw30fCL2V8NGqSVFAA/oRwarZpCZvrNJSCUUc6esDax36pEjx" - } - ] - } - }, - "windowsProfile": { - "adminUsername": "azureuser" - }, - "servicePrincipalProfile": { - "clientId": "17915f2a-09da-4729-8f62-c7121f28a4f2" - }, - "addonProfiles": { - "KubeDashboard": { - "enabled": true - } - }, - "nodeResourceGroup": "[concat('MC_private-bdc-rg_', parameters('managedClusters_bdcaksprivatecluster_name'), '_northeurope')]", - "enableRBAC": true, - "networkProfile": { - "networkPlugin": "azure", - "loadBalancerSku": "Standard", - "serviceCidr": "10.3.0.0/24", - "dnsServiceIP": "10.3.0.10", - "dockerBridgeCidr": "172.17.0.1/16", - "outboundType": "userDefinedRouting" - }, - "apiServerAccessProfile": { - "enablePrivateCluster": true - } - } - }, - { - "type": "Microsoft.Network/routeTables/routes", - "apiVersion": "2020-05-01", - "name": "[concat(parameters('routeTables_bdcaks_rt_name'), '/bdcaksroute')]", - "dependsOn": [ - "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" - ], - "properties": { - "addressPrefix": "0.0.0.0/0", - "nextHopType": "VirtualAppliance", - "nextHopIpAddress": "10.2.0.4" - } - }, - { - "type": "Microsoft.Network/routeTables/routes", - "apiVersion": "2020-05-01", - "name": "[concat(parameters('routeTables_bdcaks_rt_name'), '/bdcaksrouteinet')]", - "dependsOn": [ - "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" - ], - "properties": { - "addressPrefix": "51.104.159.190/32", - "nextHopType": "Internet" - } - }, - { - "type": "Microsoft.Network/virtualNetworks", - "apiVersion": "2020-05-01", - "name": "[parameters('virtualNetworks_bdc_vnet_name')]", - "location": "northeurope", - "dependsOn": [ - "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" - ], - "properties": { - "addressSpace": { - "addressPrefixes": [ - "10.0.0.0/8" - ] - }, - "dhcpOptions": { - "dnsServers": [] - }, - "subnets": [ - { - "name": "AzureFirewallSubnet", - "properties": { - "addressPrefix": "10.2.0.0/24", - "delegations": [], - "privateEndpointNetworkPolicies": "Enabled", - "privateLinkServiceNetworkPolicies": "Enabled" - } - }, - { - "name": "aks-subnet", - "properties": { - "addressPrefix": "10.1.0.0/16", - "routeTable": { - "id": "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" - }, - "delegations": [], - "privateEndpointNetworkPolicies": "Disabled", - "privateLinkServiceNetworkPolicies": "Enabled" - } - } - ], - "virtualNetworkPeerings": [], - "enableDdosProtection": false, - "enableVmProtection": false - } - }, - { - "type": "Microsoft.Network/virtualNetworks/subnets", - "apiVersion": "2020-05-01", - "name": "[concat(parameters('virtualNetworks_bdc_vnet_name'), '/AzureFirewallSubnet')]", - "dependsOn": [ - "[resourceId('Microsoft.Network/virtualNetworks', parameters('virtualNetworks_bdc_vnet_name'))]" - ], - "properties": { - "addressPrefix": "10.2.0.0/24", - "delegations": [], - "privateEndpointNetworkPolicies": "Enabled", - "privateLinkServiceNetworkPolicies": "Enabled" - } - }, - { - "type": "Microsoft.ContainerService/managedClusters/agentPools", - "apiVersion": "2020-06-01", - "name": "[concat(parameters('managedClusters_bdcaksprivatecluster_name'), '/nodepool1')]", - "dependsOn": [ - "[resourceId('Microsoft.ContainerService/managedClusters', parameters('managedClusters_bdcaksprivatecluster_name'))]", - "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'aks-subnet')]" - ], - "properties": { - "count": 2, - "vmSize": "Standard_D13_v2", - "osDiskSizeGB": 128, - "vnetSubnetID": "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'aks-subnet')]", - "maxPods": 30, - "type": "VirtualMachineScaleSets", - "orchestratorVersion": "1.16.13", - "enableNodePublicIP": false, - "nodeLabels": {}, - "mode": "System", - "osType": "Linux", - "nodeImageVersion": "AKSUbuntu-1604-2020.07.16" - } - }, { "type": "Microsoft.Network/azureFirewalls", "apiVersion": "2020-05-01", - "name": "[parameters('azureFirewalls_bdcaksazfw_name')]", - "location": "northeurope", + "name": "[parameters('azureFirewallName')]", + "location": "[parameters('location')]", "dependsOn": [ - "[resourceId('Microsoft.Network/publicIPAddresses', parameters('publicIPAddresses_bdcaksazfw_ip_name'))]", - "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'AzureFirewallSubnet')]" + "[resourceId('Microsoft.Network/publicIPAddresses', parameters('azureFirewallPublicIP'))]", + "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('vnetName'), 'AzureFirewallSubnet')]" ], "properties": { "sku": { @@ -263,13 +230,13 @@ }, "ipConfigurations": [ { - "name": "[concat(parameters('azureFirewalls_bdcaksazfw_name'), '-config')]", + "name": "[concat(parameters('azureFirewallName'), '-config')]", "properties": { "publicIPAddress": { - "id": "[resourceId('Microsoft.Network/publicIPAddresses', parameters('publicIPAddresses_bdcaksazfw_ip_name'))]" + "id": "[resourceId('Microsoft.Network/publicIPAddresses', parameters('azureFirewallPublicIP'))]" }, "subnet": { - "id": "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('virtualNetworks_bdc_vnet_name'), 'AzureFirewallSubnet')]" + "id": "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('vnetName'), 'AzureFirewallSubnet')]" } } } @@ -346,22 +313,97 @@ } }, { - "type": "Microsoft.Network/virtualNetworks/subnets", - "apiVersion": "2020-05-01", - "name": "[concat(parameters('virtualNetworks_bdc_vnet_name'), '/aks-subnet')]", - "dependsOn": [ - "[resourceId('Microsoft.Network/virtualNetworks', parameters('virtualNetworks_bdc_vnet_name'))]", - "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" + "type": "Microsoft.Resources/deployments", + "apiVersion": "2019-10-01", + "name": "DeployPrivateAksCluster", + "dependsOn": [ + "[variables('vnetSubnetID')]" ], + "resourceGroup": "[resourceGroup().name]", "properties": { - "addressPrefix": "10.1.0.0/16", - "routeTable": { - "id": "[resourceId('Microsoft.Network/routeTables', parameters('routeTables_bdcaks_rt_name'))]" - }, - "delegations": [], - "privateEndpointNetworkPolicies": "Disabled", - "privateLinkServiceNetworkPolicies": "Enabled" + "mode": "Incremental", + "template": { + "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", + "contentVersion": "1.0.0.0", + "resources": [ + { + "type": "Microsoft.ContainerService/managedClusters", + "apiVersion": "2020-06-01", + "name": "[parameters('aksclusterName')]", + "location": "[parameters('location')]", + "dependsOn": [ + "ClusterSubnetRoleAssignmentDeployment" + ], + "sku": { + "name": "Basic", + "tier": "Free" + }, + "properties": { + "kubernetesVersion": "[parameters('kubernetesVersion')]", + "dnsPrefix": "[parameters('dnsPrefix')]", + "agentPoolProfiles": [ + { + "name": "nodepool", + "count": "[parameters('agentCount')]", + "vmSize": "[parameters('agentVMSize')]", + "osDiskSizeGB": 128, + "vnetSubnetID":"[variables('vnetSubnetID')]", + "maxPods": 30, + "type": "VirtualMachineScaleSets", + "orchestratorVersion": "[parameters('kubernetesVersion')]", + "enableNodePublicIP": false, + "mode": "System", + "osType": "Linux", + "nodeImageVersion": "AKSUbuntu-1604-2020.07.16" + } + ], + "servicePrincipalProfile": { + "clientId": "[parameters('existingServicePrincipalClientId')]", + "secret": "[parameters('existingServicePrincipalClientSecret')]" + }, + "networkProfile": { + "networkPlugin": "azure", + "loadBalancerSku": "Standard", + "serviceCidr": "[parameters('serviceCidr')]", + "dnsServiceIP": "[parameters('dnsServiceIP')]", + "dockerBridgeCidr": "[parameters('dockerBridgeCidr')]", + "outboundType": "userDefinedRouting" + }, + "apiServerAccessProfile": { + "enablePrivateCluster": true + } + } + }, + { + "type": "Microsoft.Resources/deployments", + "name": "ClusterSubnetRoleAssignmentDeployment", + "apiVersion": "2017-05-10", + "resourceGroup": "[resourceGroup().name]", + "properties": { + "mode": "Incremental", + "template": { + "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", + "contentVersion": "1.0.0.0", + "parameters": {}, + "variables": {}, + "resources": [ + { + "type": "Microsoft.Network/virtualNetworks/providers/roleAssignments", + "apiVersion": "2017-05-01", + "name": "[concat(parameters('vnetName'),'/Microsoft.Authorization/', guid(resourceGroup().id, deployment().name))]", + "properties": { + "roleDefinitionId": "[variables('networkRoleDefinitionID')]", + "principalId": "[parameters('existingServicePrincipalObjectId')]", + "scope": "[resourceId(resourceGroup().name,'Microsoft.Network/virtualNetworks',parameters('vnetName'))]" + } + } + ] + } + } + } + ] + } + } } - } ] } \ No newline at end of file diff --git a/samples/features/sql-big-data-cluster/private-bdc/README.md b/samples/features/sql-big-data-cluster/private-bdc/README.md index 692e1049..ed33546d 100644 --- a/samples/features/sql-big-data-cluster/private-bdc/README.md +++ b/samples/features/sql-big-data-cluster/private-bdc/README.md @@ -1,2 +1,10 @@ # Deploy BDC in private AKS cluster with User-defined Route (UDR) +This repository contains : + +Bash Scripts : +- deploy-private-aks.sh +- deploy-private-aks-udr.sh +- deploy-private-bdc.sh + + From b7abae03191457b27ccd8c1aace514f1e865051e Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Fri, 14 Aug 2020 00:34:30 +0100 Subject: [PATCH 03/16] update scripts --- .../private-bdc/ARMtemplates/parameters.json | 21 - .../private-bdc/ARMtemplates/template.json | 409 ------------------ .../private-bdc/README.md | 6 +- 3 files changed, 3 insertions(+), 433 deletions(-) delete mode 100644 samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/parameters.json delete mode 100644 samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json diff --git a/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/parameters.json b/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/parameters.json deleted file mode 100644 index bb613613..00000000 --- a/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/parameters.json +++ /dev/null @@ -1,21 +0,0 @@ -{ - "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#", - "contentVersion": "1.0.0.0", - "parameters": { - "routeTables_bdcaks_rt_name": { - "value": null - }, - "virtualNetworks_bdc_vnet_name": { - "value": null - }, - "azureFirewalls_bdcaksazfw_name": { - "value": null - }, - "publicIPAddresses_bdcaksazfw_ip_name": { - "value": null - }, - "managedClusters_bdcaksprivatecluster_name": { - "value": null - } - } -} \ No newline at end of file diff --git a/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json b/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json deleted file mode 100644 index 317f6d6b..00000000 --- a/samples/features/sql-big-data-cluster/private-bdc/ARMtemplates/template.json +++ /dev/null @@ -1,409 +0,0 @@ -{ - "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#", - "contentVersion": "1.0.0.0", - "parameters": { - "aksclusterName": { - "type": "string", - "metadata": { - "description": "The name of the AKS Managed Cluster resource." - } - }, - "location": { - "type": "string", - "defaultValue": "[resourceGroup().location]", - "metadata": { - "description": "The Azure location of the AKS resource." - } - }, - "dnsPrefix": { - "type": "string", - "metadata": { - "description": "Optional DNS prefix to use with hosted Kubernetes API server FQDN." - } - }, - "agentCount": { - "defaultValue": 3, - "minValue": 1, - "maxValue": 50, - "type": "int", - "metadata": { - "description": "The number of agent nodes for the cluster. Production workloads have a recommended minimum of 3." - } - }, - "agentVMSize": { - "defaultValue": "Standard_D13_v2", - "type": "string", - "metadata": { - "description": "The recommended size of the Virtual Machine." - } - }, - "existingServicePrincipalObjectId": { - "type": "string", - "metadata": { - "description": "Object ID against which the Network Contributor roles will be assigned on the subnet" - } - }, - "existingServicePrincipalClientId": { - "type": "string", - "metadata": { - "description": "Client ID (used by cloudprovider)" - } - }, - "existingServicePrincipalClientSecret": { - "type": "securestring", - "metadata": { - "description": "The Service Principal Client Secret." - } - }, - "kubernetesVersion": { - "defaultValue": "1.16.13", - "type": "string", - "metadata": { - "description": "The version of Kubernetes." - } - }, - "serviceCidr": { - "type": "string", - "defaultValue": "10.3.0.0/24", - "metadata": { - "description": "A CIDR notation IP range from which to assign service cluster IPs." - } - }, - "dnsServiceIP": { - "type": "string", - "defaultValue": "10.3.0.10", - "metadata": { - "description": "Containers DNS server IP address." - } - }, - "dockerBridgeCidr": { - "type": "string", - "defaultValue": "172.17.0.1/16", - "metadata": { - "description": "A CIDR notation IP for Docker bridge." - } - }, - "routetableName": { - "defaultValue": "bdcaks-rt", - "type": "String" - }, - "vnetName": { - "defaultValue": "bdcaks-vnet", - "type": "String" - }, - "subnetName": { - "defaultValue": "bdcaks-subnet", - "type": "String" - }, - "azureFirewallName": { - "defaultValue": "bdcaksazfw", - "type": "String" - }, - "azureFirewallPublicIP": { - "defaultValue": "bdcaksazfw-ip", - "type": "String" - } - }, - "variables": { - "networkRoleDefinitionID":"[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Authorization/roleDefinitions/', '4d97b98b-1d4f-4787-a291-c67834d212e7')]", - "vnetSubnetID":"[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('vnetName'), parameters('subnetName'))]" - }, - "resources": [ - { - "type": "Microsoft.Network/virtualNetworks", - "apiVersion": "2020-05-01", - "name": "[parameters('vnetName')]", - "location": "[parameters('location')]", - "dependsOn": [ - "[resourceId('Microsoft.Network/routeTables', parameters('routetableName'))]" - ], - "properties": { - "addressSpace": { - "addressPrefixes": [ - "10.0.0.0/8" - ] - }, - "dhcpOptions": { - "dnsServers": [] - }, - "virtualNetworkPeerings": [], - "enableDdosProtection": false, - "enableVmProtection": false - }, - "resources": [ - { - "type": "subnets", - "apiVersion": "2020-05-01", - "location": "[parameters('location')]", - "name": "AzureFirewallSubnet", - "dependsOn": [ - "[resourceId('Microsoft.Network/virtualNetworks', parameters('vnetName'))]" - ], - "properties": { - "addressPrefix": "10.2.0.0/24", - "delegations": [], - "privateEndpointNetworkPolicies": "Enabled", - "privateLinkServiceNetworkPolicies": "Enabled" - } - }, - { - "type": "subnets", - "apiVersion": "2020-05-01", - "location": "[parameters('location')]", - "name": "[parameters('subnetName')]", - "dependsOn": [ - "[resourceId('Microsoft.Network/virtualNetworks', parameters('vnetName'))]", - "[resourceId('Microsoft.Network/routeTables', parameters('routetableName'))]" - ], - "properties": { - "addressPrefix": "10.1.0.0/16", - "routeTable": { - "id": "[resourceId('Microsoft.Network/routeTables', parameters('routetableName'))]" - }, - "delegations": [], - "privateEndpointNetworkPolicies": "Disabled", - "privateLinkServiceNetworkPolicies": "Enabled" - } - } - ] - }, - { - "type": "Microsoft.Network/publicIPAddresses", - "apiVersion": "2020-05-01", - "name": "[parameters('azureFirewallPublicIP')]", - "location": "[parameters('location')]", - "sku": { - "name": "Standard" - }, - "properties": { - "ipAddress": "51.104.159.190", - "publicIPAddressVersion": "IPv4", - "publicIPAllocationMethod": "Static", - "idleTimeoutInMinutes": 4, - "ipTags": [] - } - }, - { - "type": "Microsoft.Network/routeTables", - "apiVersion": "2020-05-01", - "name": "[parameters('routetableName')]", - "location": "[parameters('location')]", - "properties": { - "disableBgpRoutePropagation": false, - "routes": [ - { - "name": "bdcaksrouteinet", - "properties": { - "addressPrefix": "51.104.159.190/32", - "nextHopType": "Internet" - } - }, - { - "name": "bdcaksroute", - "properties": { - "addressPrefix": "0.0.0.0/0", - "nextHopType": "VirtualAppliance", - "nextHopIpAddress": "10.2.0.4" - } - } - ] - } - }, - { - "type": "Microsoft.Network/azureFirewalls", - "apiVersion": "2020-05-01", - "name": "[parameters('azureFirewallName')]", - "location": "[parameters('location')]", - "dependsOn": [ - "[resourceId('Microsoft.Network/publicIPAddresses', parameters('azureFirewallPublicIP'))]", - "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('vnetName'), 'AzureFirewallSubnet')]" - ], - "properties": { - "sku": { - "name": "AZFW_VNet", - "tier": "Standard" - }, - "threatIntelMode": "Alert", - "additionalProperties": { - "Network.DNS.EnableProxy": "True", - "Network.DNS.RequireProxyForNetworkRules": "True" - }, - "ipConfigurations": [ - { - "name": "[concat(parameters('azureFirewallName'), '-config')]", - "properties": { - "publicIPAddress": { - "id": "[resourceId('Microsoft.Network/publicIPAddresses', parameters('azureFirewallPublicIP'))]" - }, - "subnet": { - "id": "[resourceId('Microsoft.Network/virtualNetworks/subnets', parameters('vnetName'), 'AzureFirewallSubnet')]" - } - } - } - ], - "networkRuleCollections": [ - { - "name": "aksfwnr", - "properties": { - "priority": 100, - "action": { - "type": "Allow" - }, - "rules": [ - { - "name": "apiudp", - "protocols": [ - "UDP" - ], - "sourceAddresses": [ - "*" - ], - "destinationAddresses": [ - "AzureCloud.northeurope" - ], - "sourceIpGroups": [], - "destinationIpGroups": [], - "destinationFqdns": [], - "destinationPorts": [ - "1194" - ] - }, - { - "name": "apitcp", - "protocols": [ - "TCP" - ], - "sourceAddresses": [ - "*" - ], - "destinationAddresses": [ - "AzureCloud.northeurope" - ], - "sourceIpGroups": [], - "destinationIpGroups": [], - "destinationFqdns": [], - "destinationPorts": [ - "9000" - ] - }, - { - "name": "time", - "protocols": [ - "UDP" - ], - "sourceAddresses": [ - "*" - ], - "destinationAddresses": [], - "sourceIpGroups": [], - "destinationIpGroups": [], - "destinationFqdns": [ - "ntp.ubuntu.com" - ], - "destinationPorts": [ - "123" - ] - } - ] - } - } - ], - "applicationRuleCollections": [], - "natRuleCollections": [] - } - }, - { - "type": "Microsoft.Resources/deployments", - "apiVersion": "2019-10-01", - "name": "DeployPrivateAksCluster", - "dependsOn": [ - "[variables('vnetSubnetID')]" - ], - "resourceGroup": "[resourceGroup().name]", - "properties": { - "mode": "Incremental", - "template": { - "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", - "contentVersion": "1.0.0.0", - "resources": [ - { - "type": "Microsoft.ContainerService/managedClusters", - "apiVersion": "2020-06-01", - "name": "[parameters('aksclusterName')]", - "location": "[parameters('location')]", - "dependsOn": [ - "ClusterSubnetRoleAssignmentDeployment" - ], - "sku": { - "name": "Basic", - "tier": "Free" - }, - "properties": { - "kubernetesVersion": "[parameters('kubernetesVersion')]", - "dnsPrefix": "[parameters('dnsPrefix')]", - "agentPoolProfiles": [ - { - "name": "nodepool", - "count": "[parameters('agentCount')]", - "vmSize": "[parameters('agentVMSize')]", - "osDiskSizeGB": 128, - "vnetSubnetID":"[variables('vnetSubnetID')]", - "maxPods": 30, - "type": "VirtualMachineScaleSets", - "orchestratorVersion": "[parameters('kubernetesVersion')]", - "enableNodePublicIP": false, - "mode": "System", - "osType": "Linux", - "nodeImageVersion": "AKSUbuntu-1604-2020.07.16" - } - ], - "servicePrincipalProfile": { - "clientId": "[parameters('existingServicePrincipalClientId')]", - "secret": "[parameters('existingServicePrincipalClientSecret')]" - }, - "networkProfile": { - "networkPlugin": "azure", - "loadBalancerSku": "Standard", - "serviceCidr": "[parameters('serviceCidr')]", - "dnsServiceIP": "[parameters('dnsServiceIP')]", - "dockerBridgeCidr": "[parameters('dockerBridgeCidr')]", - "outboundType": "userDefinedRouting" - }, - "apiServerAccessProfile": { - "enablePrivateCluster": true - } - } - }, - { - "type": "Microsoft.Resources/deployments", - "name": "ClusterSubnetRoleAssignmentDeployment", - "apiVersion": "2017-05-10", - "resourceGroup": "[resourceGroup().name]", - "properties": { - "mode": "Incremental", - "template": { - "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", - "contentVersion": "1.0.0.0", - "parameters": {}, - "variables": {}, - "resources": [ - { - "type": "Microsoft.Network/virtualNetworks/providers/roleAssignments", - "apiVersion": "2017-05-01", - "name": "[concat(parameters('vnetName'),'/Microsoft.Authorization/', guid(resourceGroup().id, deployment().name))]", - "properties": { - "roleDefinitionId": "[variables('networkRoleDefinitionID')]", - "principalId": "[parameters('existingServicePrincipalObjectId')]", - "scope": "[resourceId(resourceGroup().name,'Microsoft.Network/virtualNetworks',parameters('vnetName'))]" - } - } - ] - } - } - } - ] - } - } - } - ] -} \ No newline at end of file diff --git a/samples/features/sql-big-data-cluster/private-bdc/README.md b/samples/features/sql-big-data-cluster/private-bdc/README.md index ed33546d..42799f58 100644 --- a/samples/features/sql-big-data-cluster/private-bdc/README.md +++ b/samples/features/sql-big-data-cluster/private-bdc/README.md @@ -3,8 +3,8 @@ This repository contains : Bash Scripts : -- deploy-private-aks.sh -- deploy-private-aks-udr.sh -- deploy-private-bdc.sh +- deploy-private-aks.sh To deploy private AKS cluster ( private endpoint ) +- deploy-private-aks-udr.sh To deploy private AKS cluster with UDR. +- deploy-private-bdc.sh To deploy Big Data Clusters ( BDC ) in private deployment mode. From 86cbe89bc67112e5ab3118e45123acf20f33c293 Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Tue, 18 Aug 2020 15:30:12 +0100 Subject: [PATCH 04/16] add details for scripts --- .../sql-big-data-cluster/deployment/README.md | 7 ++- .../deployment/private-bdc/README.md | 51 +++++++++++++++++++ .../scripts/deploy-private-aks-udr.sh | 34 ++++++++++--- .../private-bdc/scripts/deploy-private-aks.sh | 5 +- .../private-bdc/scripts/deploy-private-bdc.sh | 20 +++++++- .../private-bdc/README.md | 10 ---- 6 files changed, 106 insertions(+), 21 deletions(-) create mode 100644 samples/features/sql-big-data-cluster/deployment/private-bdc/README.md rename samples/features/sql-big-data-cluster/{ => deployment}/private-bdc/scripts/deploy-private-aks-udr.sh (82%) rename samples/features/sql-big-data-cluster/{ => deployment}/private-bdc/scripts/deploy-private-aks.sh (91%) rename samples/features/sql-big-data-cluster/{ => deployment}/private-bdc/scripts/deploy-private-bdc.sh (69%) delete mode 100644 samples/features/sql-big-data-cluster/private-bdc/README.md diff --git a/samples/features/sql-big-data-cluster/deployment/README.md b/samples/features/sql-big-data-cluster/deployment/README.md index fe5ec277..0e85dd42 100644 --- a/samples/features/sql-big-data-cluster/deployment/README.md +++ b/samples/features/sql-big-data-cluster/deployment/README.md @@ -13,4 +13,9 @@ Using the sample Python script in **aks** folder, you will deploy a Kubernetes c ## __[Push SQL Server big data cluster images to your own private Docker repository](offline/)__ -Using the sample Python script in **offline** folder, you will push the necessary images required for the deployment to your own repository. \ No newline at end of file +Using the sample Python script in **offline** folder, you will push the necessary images required for the deployment to your own repository. + +## __[Deploy SQL Server big data cluster in private mode with Azure Kubernetes service (AKS) private cluster](private-bdc/)__ + +Using the sample Python script in **private-bdc** folder, you will Deploy SQL Server big data cluster in private mode with Azure Kubernetes service (AKS) private cluster. + diff --git a/samples/features/sql-big-data-cluster/deployment/private-bdc/README.md b/samples/features/sql-big-data-cluster/deployment/private-bdc/README.md new file mode 100644 index 00000000..47e3aa3f --- /dev/null +++ b/samples/features/sql-big-data-cluster/deployment/private-bdc/README.md @@ -0,0 +1,51 @@ +# Deploy BDC in private AKS cluster with User-defined Route (UDR) + +This repository contains the scripts that you can use to deploy a private BDC cluster in Azure Kubernetes Service (AKS) with advanced networking ( CNI ). + +This repository contains 3 bash scripts : +- deploy-private-aks.sh : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster. +- deploy-private-aks-udr.sh : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster and limit egress traffic with UDR ( User-defined Routes ). +- deploy-private-bdc.sh : You can use it to deploy Big Data Clusters ( BDC ) in private deployment mode on private AKS cluster with or without User-defined routes based on your project requirements. + + +## Prerequisite + +The following table lists common big data cluster tools and how to install them: + +| Tool | Required | Description | Installation | +|---|---|---|---| +| `python` | Yes | Python is an interpreted, object-oriented, high-level programming language with dynamic semantics. Many parts of big data clusters for SQL Server use python. | [Install python](#python)| +| `azdata` | Yes | Command-line tool for installing and managing a big data cluster. | [Install](deploy-install-azdata.md) | +| `kubectl`1 | Yes | Command-line tool for monitoring the underlying Kubernetes cluster ([More info](https://kubernetes.io/docs/tasks/tools/install-kubectl/)). | [Windows](https://kubernetes.io/docs/tasks/tools/install-kubectl/#install-with-powershell-from-psgallery) \| [Linux](https://kubernetes.io/docs/tasks/tools/install-kubectl/#install-using-native-package-management) | +| **Azure Data Studio** | Yes | Cross-platform graphical tool for querying SQL Server. | [Install](https://aka.ms/getazuredatastudio) | +| **Data Virtualization extension** | Yes | Extension for Azure Data Studio that provides a Data Virtualization wizard. | [Install](../azure-data-studio/data-virtualization-extension.md) | +| **Azure CLI**2 | For AKS | Modern command-line interface for managing Azure services. Used with AKS big data cluster deployments ([More info](https://docs.microsoft.com/cli/azure/?view=azure-cli-latest)). | [Install](https://docs.microsoft.com/cli/azure/install-azure-cli?view=azure-cli-latest) | +| **mssql-cli** | Optional | Modern command-line interface for querying SQL Server ([More info](../tools/mssql-cli.md)). | [Windows](https://github.com/dbcli/mssql-cli/blob/master/doc/installation/windows.md) \| [Linux](https://github.com/dbcli/mssql-cli/blob/master/doc/installation/linux.md) | +| **sqlcmd** | For some scripts | Legacy command-line tool for querying SQL Server ([More info](https://docs.microsoft.com/sql/tools/sqlcmd-utility?view=sql-server-ver15)). You might need to install the Microsoft ODBC Driver 11 for SQL Server before installing the SQLCMD package. | [Windows](https://www.microsoft.com/download/details.aspx?id=36433) \| [Linux](../linux/sql-server-linux-setup-tools.md) | +| `curl` 3 | For some scripts | Command-line tool for transferring data with URLs. | [Windows](https://curl.haxx.se/windows/) \| Linux: install curl package | +| `oc` | Required for Red Hat OpenShift and Azure Redhat OpenShift deployments. |`oc` is the Open Shift command line interface (CLI). | [Installing the CLI](https://docs.openshift.com/container-platform/4.4/cli_reference/openshift_cli/getting-started-cli.html#installing-the-cli) + + + +## Instructions + +1. Download the script on the VM you are planning to use for the deployment + +``` bash +curl --output setup-bdc.sh https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-bdc/ubuntu-single-node-vm/deploy-private-aks.sh +``` + +2. Make the script executable + +``` bash +chmod +x deploy-private-aks.sh +``` + +3. Run the script (make sure you are running with sudo) + +``` bash +sudo ./deploy-private-aks.sh +``` + + + diff --git a/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks-udr.sh similarity index 82% rename from samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks-udr.sh rename to samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks-udr.sh index 5102fded..e33ee6b2 100644 --- a/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks-udr.sh @@ -1,6 +1,19 @@ #!/bin/bash -export SUBID= +# Get Subscription ID and service principles as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. +# +while true; do + read -s -p "Your Azure Subscription: " subscription + echo + read -s -p "Your service principles ID: " sp_id + echo + read -s -p "Your service principles Password: " sp_pwd + +done + +# Define a set of environment variables to be used in resource creations. + +export SUBID=$subscription export REGION_NAME=northeurope export RESOURCE_GROUP=private-bdc-rg @@ -16,9 +29,10 @@ export FWROUTE_NAME=bdcaksroute export FWROUTE_NAME_INTERNET=bdcaksrouteinet - +# Create Azure Resource Group az group create -n $RESOURCE_GROUP -l $REGION_NAME +# Create Azure Virtual Network to host your AKS cluster az network vnet create \ --resource-group $RESOURCE_GROUP \ --location $REGION_NAME \ @@ -35,29 +49,34 @@ SUBNET_ID=$(az network vnet subnet show \ --query id -o tsv) +# Add Azure firewall extension az extension add --name azure-firewall # Dedicated subnet for Azure Firewall (Firewall name cannot be changed) - az network vnet subnet create \ --resource-group $RESOURCE_GROUP \ --vnet-name $VNET_NAME \ --name AzureFirewallSubnet \ --address-prefix 10.2.0.0/24 +# Create Azure firewall az network firewall create -g $RESOURCE_GROUP -n $FWNAME -l $REGION_NAME --enable-dns-proxy true +# Create public IP for Azure Firewall az network public-ip create -g $RESOURCE_GROUP -n $FWPUBIP -l $REGION_NAME --sku "Standard" +# Create IP configurations for Azure Firewall az network firewall ip-config create -g $RESOURCE_GROUP -f $FWNAME -n $FWIPCONFIG_NAME --public-ip-address $FWPUBIP --vnet-name $VNET_NAME - +# Getting public and private IP addresses for Azure Firewall export FWPUBLIC_IP=$(az network public-ip show -g $RESOURCE_GROUP -n $FWPUBIP --query "ipAddress" -o tsv) export FWPRIVATE_IP=$(az network firewall show -g $RESOURCE_GROUP -n $FWNAME --query "ipConfigurations[0].privateIpAddress" -o tsv) +## Create an User defined route table az network route-table create -g $RESOURCE_GROUP --name $FWROUTE_TABLE_NAME +# Create User defined routes az network route-table route create -g $RESOURCE_GROUP --name $FWROUTE_NAME --route-table-name $FWROUTE_TABLE_NAME --address-prefix 0.0.0.0/0 --next-hop-type VirtualAppliance --next-hop-ip-address $FWPRIVATE_IP --subscription $SUBID az network route-table route create -g $RESOURCE_GROUP --name $FWROUTE_NAME_INTERNET --route-table-name $FWROUTE_TABLE_NAME --address-prefix $FWPUBLIC_IP/32 --next-hop-type Internet @@ -84,19 +103,20 @@ az network vnet subnet update -g $RESOURCE_GROUP --vnet-name $VNET_NAME --name $ az ad sp create-for-rbac -n "bdcaks-sp" --skip-assignment -export APPID= -export PASSWORD=< your service principle password > +export APPID=$sp_id +export PASSWORD=$sp_pwd export VNETID=$(az network vnet show -g $RESOURCE_GROUP --name $VNET_NAME --query id -o tsv) # Assign SP Permission to VNET az role assignment create --assignee $APPID --scope $VNETID --role "Network Contributor" - +# Assign SP Permission to route table export RTID=$(az network route-table show -g $RESOURCE_GROUP -n $FWROUTE_TABLE_NAME --query id -o tsv) az role assignment create --assignee $APPID --scope $RTID --role "Network Contributor" +# Create AKS Cluster az aks create \ --resource-group $RESOURCE_GROUP \ --location $REGION_NAME \ diff --git a/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks.sh b/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks.sh similarity index 91% rename from samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks.sh rename to samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks.sh index 6ce64405..2469ea40 100644 --- a/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-aks.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks.sh @@ -8,8 +8,11 @@ export SUBNET_NAME=aks-subnet export VNET_NAME=bdc-vnet export AKS_NAME=bdcaksprivatecluster + +# Create Azure Resource Group az group create -n $RESOURCE_GROUP -l $REGION_NAME +# Create Azure Virtual Network to host your AKS clus az network vnet create \ --resource-group $RESOURCE_GROUP \ --location $REGION_NAME \ @@ -17,7 +20,6 @@ az network vnet create \ --address-prefixes 10.0.0.0/8 \ --subnet-name $SUBNET_NAME \ --subnet-prefix 10.1.0.0/16 - SUBNET_ID=$(az network vnet subnet show \ --resource-group $RESOURCE_GROUP \ @@ -25,6 +27,7 @@ SUBNET_ID=$(az network vnet subnet show \ --name $SUBNET_NAME \ --query id -o tsv) +# Create AKS Cluster az aks create \ --resource-group $RESOURCE_GROUP \ --name $AKS_NAME \ diff --git a/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-bdc.sh b/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-bdc.sh similarity index 69% rename from samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-bdc.sh rename to samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-bdc.sh index f674b856..394bf9f7 100644 --- a/samples/features/sql-big-data-cluster/private-bdc/scripts/deploy-private-bdc.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-bdc.sh @@ -1,7 +1,23 @@ #!/bin/bash +# Get password as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. +# +while true; do + read -s -p "Create Admin username for Big Data Cluster: " bdcadmin + echo + read -s -p "Create Password for Big Data Cluster: " password + echo + read -s -p "Confirm your Password: " password2 + echo + [ "$password" = "$password2" ] && break + echo "Password mismatch. Please try again." +done + + +# Create BDC custom profile azdata bdc config init --source aks-dev-test --target private-bdc-aks --force +# Configurations for private BDC deployment azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.docker.imageTag=2019-CU6-ubuntu-16.04" azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.storage.data.className=default" azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.storage.logs.className=default" @@ -17,8 +33,8 @@ azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.appp # azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.master.spec.endpoints[1].serviceType= NodePort" -export AZDATA_USERNAME= -export AZDATA_PASSWORD=< your bdcadmin password> +export AZDATA_USERNAME=$bdcadmin +export AZDATA_PASSWORD=$password export ACCEPT_EULA=yes #accept agreement azdata bdc create --config-profile private-bdc-aks --accept-eula yes diff --git a/samples/features/sql-big-data-cluster/private-bdc/README.md b/samples/features/sql-big-data-cluster/private-bdc/README.md deleted file mode 100644 index 42799f58..00000000 --- a/samples/features/sql-big-data-cluster/private-bdc/README.md +++ /dev/null @@ -1,10 +0,0 @@ -# Deploy BDC in private AKS cluster with User-defined Route (UDR) - -This repository contains : - -Bash Scripts : -- deploy-private-aks.sh To deploy private AKS cluster ( private endpoint ) -- deploy-private-aks-udr.sh To deploy private AKS cluster with UDR. -- deploy-private-bdc.sh To deploy Big Data Clusters ( BDC ) in private deployment mode. - - From 6208c508152e7c69d8609ea8f4e649dfaefc8b9a Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Wed, 19 Aug 2020 23:15:04 +0100 Subject: [PATCH 05/16] adjust upon suggestions --- .../sql-big-data-cluster/deployment/README.md | 4 +- .../{private-bdc => private-aks}/README.md | 4 +- .../scripts/deploy-bdc.sh} | 19 +++++---- .../scripts/deploy-private-aks-udr.sh | 40 +++++++++---------- .../scripts/deploy-private-aks.sh | 8 ++-- 5 files changed, 40 insertions(+), 35 deletions(-) rename samples/features/sql-big-data-cluster/deployment/{private-bdc => private-aks}/README.md (97%) rename samples/features/sql-big-data-cluster/deployment/{private-bdc/scripts/deploy-private-bdc.sh => private-aks/scripts/deploy-bdc.sh} (73%) rename samples/features/sql-big-data-cluster/deployment/{private-bdc => private-aks}/scripts/deploy-private-aks-udr.sh (82%) rename samples/features/sql-big-data-cluster/deployment/{private-bdc => private-aks}/scripts/deploy-private-aks.sh (85%) diff --git a/samples/features/sql-big-data-cluster/deployment/README.md b/samples/features/sql-big-data-cluster/deployment/README.md index 0e85dd42..b5c7d975 100644 --- a/samples/features/sql-big-data-cluster/deployment/README.md +++ b/samples/features/sql-big-data-cluster/deployment/README.md @@ -15,7 +15,7 @@ Using the sample Python script in **aks** folder, you will deploy a Kubernetes c Using the sample Python script in **offline** folder, you will push the necessary images required for the deployment to your own repository. -## __[Deploy SQL Server big data cluster in private mode with Azure Kubernetes service (AKS) private cluster](private-bdc/)__ +## __[Deploy SQL Server big data clusters (BDC) with Azure Kubernetes service (AKS) private cluster](private-aks/)__ -Using the sample Python script in **private-bdc** folder, you will Deploy SQL Server big data cluster in private mode with Azure Kubernetes service (AKS) private cluster. +Using the sample Python script in **private-aks** folder, you will Deploy SQL Server big data cluster in private mode with Azure Kubernetes service (AKS) private cluster. diff --git a/samples/features/sql-big-data-cluster/deployment/private-bdc/README.md b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md similarity index 97% rename from samples/features/sql-big-data-cluster/deployment/private-bdc/README.md rename to samples/features/sql-big-data-cluster/deployment/private-aks/README.md index 47e3aa3f..5659d662 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-bdc/README.md +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md @@ -1,6 +1,6 @@ # Deploy BDC in private AKS cluster with User-defined Route (UDR) -This repository contains the scripts that you can use to deploy a private BDC cluster in Azure Kubernetes Service (AKS) with advanced networking ( CNI ). +This repository contains the scripts that you can use to deploy a BDC cluster in Azure Kubernetes Service (AKS) private cluster with advanced networking ( CNI ). This repository contains 3 bash scripts : - deploy-private-aks.sh : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster. @@ -8,7 +8,7 @@ This repository contains 3 bash scripts : - deploy-private-bdc.sh : You can use it to deploy Big Data Clusters ( BDC ) in private deployment mode on private AKS cluster with or without User-defined routes based on your project requirements. -## Prerequisite +## Prerequisites The following table lists common big data cluster tools and how to install them: diff --git a/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-bdc.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh similarity index 73% rename from samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-bdc.sh rename to samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh index 394bf9f7..38d0aad9 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-bdc.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh @@ -1,7 +1,7 @@ #!/bin/bash -# Get password as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. -# +#Get password as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. + while true; do read -s -p "Create Admin username for Big Data Cluster: " bdcadmin echo @@ -14,10 +14,10 @@ while true; do done -# Create BDC custom profile +#Create BDC custom profile azdata bdc config init --source aks-dev-test --target private-bdc-aks --force -# Configurations for private BDC deployment +#Configurations for private BDC deployment azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.docker.imageTag=2019-CU6-ubuntu-16.04" azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.storage.data.className=default" azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.storage.logs.className=default" @@ -29,12 +29,17 @@ azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.mast azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.gateway.spec.endpoints[0].serviceType=NodePort" azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.appproxy.spec.endpoints[0].serviceType=NodePort" -# In case you're deploying BDC in HA mode ( aks-dev-test-ha profile ) please also use the following command -# azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.master.spec.endpoints[1].serviceType= NodePort" +#In case you're deploying BDC in HA mode ( aks-dev-test-ha profile ) please also use the following command +#azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.master.spec.endpoints[1].serviceType= NodePort" export AZDATA_USERNAME=$bdcadmin export AZDATA_PASSWORD=$password -export ACCEPT_EULA=yes #accept agreement azdata bdc create --config-profile private-bdc-aks --accept-eula yes + +#Login and get endpoint list for the cluster. + +azdata login -n mssql-cluster + +azdata bdc endpoint list --output table diff --git a/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh similarity index 82% rename from samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks-udr.sh rename to samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh index e33ee6b2..76ce79f2 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh @@ -1,7 +1,7 @@ #!/bin/bash -# Get Subscription ID and service principles as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. -# +#Get Subscription ID and service principles as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. + while true; do read -s -p "Your Azure Subscription: " subscription echo @@ -11,7 +11,7 @@ while true; do done -# Define a set of environment variables to be used in resource creations. +#Define a set of environment variables to be used in resource creations. export SUBID=$subscription @@ -29,10 +29,10 @@ export FWROUTE_NAME=bdcaksroute export FWROUTE_NAME_INTERNET=bdcaksrouteinet -# Create Azure Resource Group +#Create Azure Resource Group az group create -n $RESOURCE_GROUP -l $REGION_NAME -# Create Azure Virtual Network to host your AKS cluster +#Create Azure Virtual Network to host your AKS cluster az network vnet create \ --resource-group $RESOURCE_GROUP \ --location $REGION_NAME \ @@ -49,57 +49,57 @@ SUBNET_ID=$(az network vnet subnet show \ --query id -o tsv) -# Add Azure firewall extension +#Add Azure firewall extension az extension add --name azure-firewall -# Dedicated subnet for Azure Firewall (Firewall name cannot be changed) +#Dedicated subnet for Azure Firewall (Firewall name cannot be changed) az network vnet subnet create \ --resource-group $RESOURCE_GROUP \ --vnet-name $VNET_NAME \ --name AzureFirewallSubnet \ --address-prefix 10.2.0.0/24 -# Create Azure firewall +#Create Azure firewall az network firewall create -g $RESOURCE_GROUP -n $FWNAME -l $REGION_NAME --enable-dns-proxy true -# Create public IP for Azure Firewall +#Create public IP for Azure Firewall az network public-ip create -g $RESOURCE_GROUP -n $FWPUBIP -l $REGION_NAME --sku "Standard" -# Create IP configurations for Azure Firewall +#Create IP configurations for Azure Firewall az network firewall ip-config create -g $RESOURCE_GROUP -f $FWNAME -n $FWIPCONFIG_NAME --public-ip-address $FWPUBIP --vnet-name $VNET_NAME -# Getting public and private IP addresses for Azure Firewall +#Getting public and private IP addresses for Azure Firewall export FWPUBLIC_IP=$(az network public-ip show -g $RESOURCE_GROUP -n $FWPUBIP --query "ipAddress" -o tsv) export FWPRIVATE_IP=$(az network firewall show -g $RESOURCE_GROUP -n $FWNAME --query "ipConfigurations[0].privateIpAddress" -o tsv) -## Create an User defined route table +#Create an User defined route table az network route-table create -g $RESOURCE_GROUP --name $FWROUTE_TABLE_NAME -# Create User defined routes +#Create User defined routes az network route-table route create -g $RESOURCE_GROUP --name $FWROUTE_NAME --route-table-name $FWROUTE_TABLE_NAME --address-prefix 0.0.0.0/0 --next-hop-type VirtualAppliance --next-hop-ip-address $FWPRIVATE_IP --subscription $SUBID az network route-table route create -g $RESOURCE_GROUP --name $FWROUTE_NAME_INTERNET --route-table-name $FWROUTE_TABLE_NAME --address-prefix $FWPUBLIC_IP/32 --next-hop-type Internet -# Add FW Network Rules +#Add FW Network Rules az network firewall network-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwnr' -n 'apiudp' --protocols 'UDP' --source-addresses '*' --destination-addresses "AzureCloud.$REGION_NAME" --destination-ports 1194 --action allow --priority 100 az network firewall network-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwnr' -n 'apitcp' --protocols 'TCP' --source-addresses '*' --destination-addresses "AzureCloud.$REGION_NAME" --destination-ports 9000 az network firewall network-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwnr' -n 'time' --protocols 'UDP' --source-addresses '*' --destination-fqdns 'ntp.ubuntu.com' --destination-ports 123 -# Add FW Application Rules +#Add FW Application Rules az network firewall application-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwar' -n 'fqdn' --source-addresses '*' --protocols 'http=80' 'https=443' --fqdn-tags "AzureKubernetesService" --action allow --priority 100 -# Associate User defined route table (UDR) to AKS cluster where deployed BDC previsouly +#Associate User defined route table (UDR) to AKS cluster where deployed BDC previsouly az network vnet subnet update -g $RESOURCE_GROUP --vnet-name $VNET_NAME --name $SUBNET_NAME --route-table $FWROUTE_TABLE_NAME -# Create SP and Assign Permission to Virtual Network +#Create SP and Assign Permission to Virtual Network az ad sp create-for-rbac -n "bdcaks-sp" --skip-assignment @@ -107,16 +107,16 @@ export APPID=$sp_id export PASSWORD=$sp_pwd export VNETID=$(az network vnet show -g $RESOURCE_GROUP --name $VNET_NAME --query id -o tsv) -# Assign SP Permission to VNET +#Assign SP Permission to VNET az role assignment create --assignee $APPID --scope $VNETID --role "Network Contributor" -# Assign SP Permission to route table +#Assign SP Permission to route table export RTID=$(az network route-table show -g $RESOURCE_GROUP -n $FWROUTE_TABLE_NAME --query id -o tsv) az role assignment create --assignee $APPID --scope $RTID --role "Network Contributor" -# Create AKS Cluster +#Create AKS Cluster az aks create \ --resource-group $RESOURCE_GROUP \ --location $REGION_NAME \ diff --git a/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh similarity index 85% rename from samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks.sh rename to samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh index 2469ea40..bebb0038 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-bdc/scripts/deploy-private-aks.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh @@ -1,6 +1,6 @@ #!/bin/bash -# Define a set of environment variables to be used in resource creations. +#Define a set of environment variables to be used in resource creations. export REGION_NAME=northeurope export RESOURCE_GROUP=private-bdc-aks-rg @@ -9,10 +9,10 @@ export VNET_NAME=bdc-vnet export AKS_NAME=bdcaksprivatecluster -# Create Azure Resource Group +#Create Azure Resource Group az group create -n $RESOURCE_GROUP -l $REGION_NAME -# Create Azure Virtual Network to host your AKS clus +#Create Azure Virtual Network to host your AKS clus az network vnet create \ --resource-group $RESOURCE_GROUP \ --location $REGION_NAME \ @@ -27,7 +27,7 @@ SUBNET_ID=$(az network vnet subnet show \ --name $SUBNET_NAME \ --query id -o tsv) -# Create AKS Cluster +#Create AKS Cluster az aks create \ --resource-group $RESOURCE_GROUP \ --name $AKS_NAME \ From e9f53b13f279bbbd415d9235af4e6628f5edface Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Thu, 20 Aug 2020 00:10:02 +0100 Subject: [PATCH 06/16] adjustment --- .../deployment/private-aks/README.md | 52 +++++++++++++++++-- .../private-aks/scripts/deploy-bdc.sh | 2 +- .../scripts/deploy-private-aks-udr.sh | 13 ++++- 3 files changed, 59 insertions(+), 8 deletions(-) diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/README.md b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md index 5659d662..b45f6062 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/README.md +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md @@ -3,13 +3,15 @@ This repository contains the scripts that you can use to deploy a BDC cluster in Azure Kubernetes Service (AKS) private cluster with advanced networking ( CNI ). This repository contains 3 bash scripts : -- deploy-private-aks.sh : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster. -- deploy-private-aks-udr.sh : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster and limit egress traffic with UDR ( User-defined Routes ). -- deploy-private-bdc.sh : You can use it to deploy Big Data Clusters ( BDC ) in private deployment mode on private AKS cluster with or without User-defined routes based on your project requirements. +- **deploy-private-aks.sh** : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster. +- **deploy-private-aks-udr.sh** : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster and limit egress traffic with UDR ( User-defined Routes ). +- **deploy-bdc.sh** : You can use it to deploy Big Data Clusters ( BDC ) in private deployment mode on private AKS cluster with or without User-defined routes based on your project requirements. ## Prerequisites +You can run those scripts on the following client envionrment with Linux OS or WSL/WSL2. + The following table lists common big data cluster tools and how to install them: | Tool | Required | Description | Installation | @@ -29,10 +31,12 @@ The following table lists common big data cluster tools and how to install them: ## Instructions -1. Download the script on the VM you are planning to use for the deployment +### deploy-private-aks.sh + +1. Download the script on the location that you are planning to use for the deployment ``` bash -curl --output setup-bdc.sh https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-bdc/ubuntu-single-node-vm/deploy-private-aks.sh +curl --output setup-bdc.sh https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh ``` 2. Make the script executable @@ -47,5 +51,43 @@ chmod +x deploy-private-aks.sh sudo ./deploy-private-aks.sh ``` +### deploy-private-aks-udr.sh +1. Download the script on the location that you are planning to use for the deployment + +``` bash +curl --output setup-bdc.sh https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +``` + +2. Make the script executable + +``` bash +chmod +x deploy-private-aks-udr.sh +``` + +3. Run the script (make sure you are running with sudo) + +``` bash +sudo ./deploy-private-aks-udr.sh +``` + +### deploy-bdc.sh + +1. Download the script on the location that you are planning to use for the deployment + +``` bash +curl --output setup-bdc.sh https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh +``` + +2. Make the script executable + +``` bash +chmod +x deploy-bdc.sh +``` + +3. Run the script (make sure you are running with sudo) + +``` bash +sudo ./deploy-bdc.sh +``` diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh index 38d0aad9..4f56ddb7 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh @@ -17,7 +17,7 @@ done #Create BDC custom profile azdata bdc config init --source aks-dev-test --target private-bdc-aks --force -#Configurations for private BDC deployment +#Configurations for BDC deployment azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.docker.imageTag=2019-CU6-ubuntu-16.04" azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.storage.data.className=default" azdata bdc config replace -c private-bdc-aks/control.json -j "$.spec.storage.logs.className=default" diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh index 76ce79f2..11302b4e 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh @@ -8,6 +8,10 @@ while true; do read -s -p "Your service principles ID: " sp_id echo read -s -p "Your service principles Password: " sp_pwd + echo + read -s -p "Your Resource Group Name: " resourcegroup + echo + read -s -p "In which region you're deploying " region done @@ -15,8 +19,8 @@ done export SUBID=$subscription -export REGION_NAME=northeurope -export RESOURCE_GROUP=private-bdc-rg +export REGION_NAME=$region +export RESOURCE_GROUP=$resourcegroup export SUBNET_NAME=aks-subnet export VNET_NAME=bdc-vnet export AKS_NAME=bdcaksprivatecluster @@ -28,6 +32,8 @@ export FWROUTE_TABLE_NAME=bdcaks-rt export FWROUTE_NAME=bdcaksroute export FWROUTE_NAME_INTERNET=bdcaksrouteinet +#Set Azure subscription current in use +az account set --subscription $subscription #Create Azure Resource Group az group create -n $RESOURCE_GROUP -l $REGION_NAME @@ -134,3 +140,6 @@ az aks create \ --node-vm-size Standard_D13_v2 \ --node-count 2 \ --generate-ssh-keys + + + From fef9236299d76ce038484975ce7e84468b95e3ac Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Thu, 20 Aug 2020 00:15:36 +0100 Subject: [PATCH 07/16] adjustment --- .../deployment/private-aks/scripts/deploy-bdc.sh | 8 +++----- .../private-aks/scripts/deploy-private-aks-udr.sh | 7 +------ .../deployment/private-aks/scripts/deploy-private-aks.sh | 3 +-- 3 files changed, 5 insertions(+), 13 deletions(-) diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh index 4f56ddb7..043bc80f 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh @@ -1,7 +1,7 @@ #!/bin/bash #Get password as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. - +# while true; do read -s -p "Create Admin username for Big Data Cluster: " bdcadmin echo @@ -30,16 +30,14 @@ azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.gate azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.appproxy.spec.endpoints[0].serviceType=NodePort" #In case you're deploying BDC in HA mode ( aks-dev-test-ha profile ) please also use the following command -#azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.master.spec.endpoints[1].serviceType= NodePort" - - +#azdata bdc config replace -c private-bdc-aks /bdc.json -j "$.spec.resources.master.spec.endpoints[1].serviceType=NodePort" export AZDATA_USERNAME=$bdcadmin export AZDATA_PASSWORD=$password azdata bdc create --config-profile private-bdc-aks --accept-eula yes #Login and get endpoint list for the cluster. - +# azdata login -n mssql-cluster azdata bdc endpoint list --output table diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh index 11302b4e..c2a3addd 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh @@ -1,7 +1,6 @@ #!/bin/bash - #Get Subscription ID and service principles as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. - +# while true; do read -s -p "Your Azure Subscription: " subscription echo @@ -16,7 +15,6 @@ while true; do done #Define a set of environment variables to be used in resource creations. - export SUBID=$subscription export REGION_NAME=$region @@ -89,13 +87,11 @@ az network route-table route create -g $RESOURCE_GROUP --name $FWROUTE_NAME_INTE #Add FW Network Rules - az network firewall network-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwnr' -n 'apiudp' --protocols 'UDP' --source-addresses '*' --destination-addresses "AzureCloud.$REGION_NAME" --destination-ports 1194 --action allow --priority 100 az network firewall network-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwnr' -n 'apitcp' --protocols 'TCP' --source-addresses '*' --destination-addresses "AzureCloud.$REGION_NAME" --destination-ports 9000 az network firewall network-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwnr' -n 'time' --protocols 'UDP' --source-addresses '*' --destination-fqdns 'ntp.ubuntu.com' --destination-ports 123 #Add FW Application Rules - az network firewall application-rule create -g $RESOURCE_GROUP -f $FWNAME --collection-name 'aksfwar' -n 'fqdn' --source-addresses '*' --protocols 'http=80' 'https=443' --fqdn-tags "AzureKubernetesService" --action allow --priority 100 #Associate User defined route table (UDR) to AKS cluster where deployed BDC previsouly @@ -106,7 +102,6 @@ az network vnet subnet update -g $RESOURCE_GROUP --vnet-name $VNET_NAME --name $ #Create SP and Assign Permission to Virtual Network - az ad sp create-for-rbac -n "bdcaks-sp" --skip-assignment export APPID=$sp_id diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh index bebb0038..17846c9b 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh @@ -1,7 +1,6 @@ #!/bin/bash - #Define a set of environment variables to be used in resource creations. - +# export REGION_NAME=northeurope export RESOURCE_GROUP=private-bdc-aks-rg export SUBNET_NAME=aks-subnet From 734d22c3f370d75277ec0eceaa76885169508d93 Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Thu, 20 Aug 2020 00:21:47 +0100 Subject: [PATCH 08/16] add space --- .../deployment/private-aks/scripts/deploy-private-aks-udr.sh | 1 - 1 file changed, 1 deletion(-) diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh index c2a3addd..80343843 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh @@ -109,7 +109,6 @@ export PASSWORD=$sp_pwd export VNETID=$(az network vnet show -g $RESOURCE_GROUP --name $VNET_NAME --query id -o tsv) #Assign SP Permission to VNET - az role assignment create --assignee $APPID --scope $VNETID --role "Network Contributor" #Assign SP Permission to route table From 72f708f65cb5c47f53b7be7a6ed563a31fd54a4f Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Thu, 20 Aug 2020 00:31:44 +0100 Subject: [PATCH 09/16] add params --- .../sql-big-data-cluster/deployment/README.md | 2 +- .../deployment/private-aks/README.md | 16 ++------------ .../scripts/deploy-private-aks-udr.sh | 9 ++++---- .../private-aks/scripts/deploy-private-aks.sh | 22 +++++++++++++++++-- 4 files changed, 27 insertions(+), 22 deletions(-) diff --git a/samples/features/sql-big-data-cluster/deployment/README.md b/samples/features/sql-big-data-cluster/deployment/README.md index b5c7d975..b8d629e3 100644 --- a/samples/features/sql-big-data-cluster/deployment/README.md +++ b/samples/features/sql-big-data-cluster/deployment/README.md @@ -17,5 +17,5 @@ Using the sample Python script in **offline** folder, you will push the necessar ## __[Deploy SQL Server big data clusters (BDC) with Azure Kubernetes service (AKS) private cluster](private-aks/)__ -Using the sample Python script in **private-aks** folder, you will Deploy SQL Server big data cluster in private mode with Azure Kubernetes service (AKS) private cluster. +Using the sample Python script in **private-aks** folder, you will Deploy SQL Server big data cluster in in your private network with Azure Kubernetes service (AKS) private cluster. diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/README.md b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md index b45f6062..15540ee5 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/README.md +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md @@ -12,21 +12,9 @@ This repository contains 3 bash scripts : You can run those scripts on the following client envionrment with Linux OS or WSL/WSL2. -The following table lists common big data cluster tools and how to install them: - -| Tool | Required | Description | Installation | -|---|---|---|---| -| `python` | Yes | Python is an interpreted, object-oriented, high-level programming language with dynamic semantics. Many parts of big data clusters for SQL Server use python. | [Install python](#python)| -| `azdata` | Yes | Command-line tool for installing and managing a big data cluster. | [Install](deploy-install-azdata.md) | -| `kubectl`1 | Yes | Command-line tool for monitoring the underlying Kubernetes cluster ([More info](https://kubernetes.io/docs/tasks/tools/install-kubectl/)). | [Windows](https://kubernetes.io/docs/tasks/tools/install-kubectl/#install-with-powershell-from-psgallery) \| [Linux](https://kubernetes.io/docs/tasks/tools/install-kubectl/#install-using-native-package-management) | -| **Azure Data Studio** | Yes | Cross-platform graphical tool for querying SQL Server. | [Install](https://aka.ms/getazuredatastudio) | -| **Data Virtualization extension** | Yes | Extension for Azure Data Studio that provides a Data Virtualization wizard. | [Install](../azure-data-studio/data-virtualization-extension.md) | -| **Azure CLI**2 | For AKS | Modern command-line interface for managing Azure services. Used with AKS big data cluster deployments ([More info](https://docs.microsoft.com/cli/azure/?view=azure-cli-latest)). | [Install](https://docs.microsoft.com/cli/azure/install-azure-cli?view=azure-cli-latest) | -| **mssql-cli** | Optional | Modern command-line interface for querying SQL Server ([More info](../tools/mssql-cli.md)). | [Windows](https://github.com/dbcli/mssql-cli/blob/master/doc/installation/windows.md) \| [Linux](https://github.com/dbcli/mssql-cli/blob/master/doc/installation/linux.md) | -| **sqlcmd** | For some scripts | Legacy command-line tool for querying SQL Server ([More info](https://docs.microsoft.com/sql/tools/sqlcmd-utility?view=sql-server-ver15)). You might need to install the Microsoft ODBC Driver 11 for SQL Server before installing the SQLCMD package. | [Windows](https://www.microsoft.com/download/details.aspx?id=36433) \| [Linux](../linux/sql-server-linux-setup-tools.md) | -| `curl` 3 | For some scripts | Command-line tool for transferring data with URLs. | [Windows](https://curl.haxx.se/windows/) \| Linux: install curl package | -| `oc` | Required for Red Hat OpenShift and Azure Redhat OpenShift deployments. |`oc` is the Open Shift command line interface (CLI). | [Installing the CLI](https://docs.openshift.com/container-platform/4.4/cli_reference/openshift_cli/getting-started-cli.html#installing-the-cli) +The following table link listed common big data cluster tools and how to install them: +https://docs.microsoft.com/en-us/sql/big-data-cluster/deploy-big-data-tools?view=sql-server-ver15 ## Instructions diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh index 80343843..65f1f012 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh @@ -4,14 +4,13 @@ while true; do read -s -p "Your Azure Subscription: " subscription echo - read -s -p "Your service principles ID: " sp_id - echo - read -s -p "Your service principles Password: " sp_pwd - echo read -s -p "Your Resource Group Name: " resourcegroup echo read -s -p "In which region you're deploying " region - + echo + read -s -p "Your service principles ID: " sp_id + echo + read -s -p "Your service principles Password: " sp_pwd done #Define a set of environment variables to be used in resource creations. diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh index 17846c9b..f461ef22 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh @@ -1,12 +1,30 @@ #!/bin/bash #Define a set of environment variables to be used in resource creations. # -export REGION_NAME=northeurope -export RESOURCE_GROUP=private-bdc-aks-rg + +#!/bin/bash +#Get Subscription ID and service principles as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. +# +while true; do + read -s -p "Your Azure Subscription: " subscription + echo + read -s -p "Your Resource Group Name: " resourcegroup + echo + read -s -p "In which region you're deploying " region + echo +done + +#Define a set of environment variables to be used in resource creations. +export SUBID=$subscription + +export REGION_NAME=$region +export RESOURCE_GROUP=$resourcegroup export SUBNET_NAME=aks-subnet export VNET_NAME=bdc-vnet export AKS_NAME=bdcaksprivatecluster +#Set Azure subscription current in use +az account set --subscription $subscription #Create Azure Resource Group az group create -n $RESOURCE_GROUP -l $REGION_NAME From 023d62b7bcfaa4a65fd25a71f9da4fa06e2da3f3 Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Thu, 20 Aug 2020 00:38:28 +0100 Subject: [PATCH 10/16] add chagnes --- .../private-aks/scripts/deploy-private-aks-udr.sh | 8 ++++---- .../deployment/private-aks/scripts/deploy-private-aks.sh | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh index 65f1f012..0ea137c8 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh @@ -1,16 +1,16 @@ #!/bin/bash -#Get Subscription ID and service principles as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. +#Get Subscription ID and Azure service principal as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. # while true; do read -s -p "Your Azure Subscription: " subscription echo read -s -p "Your Resource Group Name: " resourcegroup echo - read -s -p "In which region you're deploying " region + read -s -p "In which region you're deploying: " region echo - read -s -p "Your service principles ID: " sp_id + read -s -p "Your Azure service principal ID: " sp_id echo - read -s -p "Your service principles Password: " sp_pwd + read -s -p "Your Azure service principal Password: " sp_pwd done #Define a set of environment variables to be used in resource creations. diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh index f461ef22..e5a492e4 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh @@ -3,7 +3,7 @@ # #!/bin/bash -#Get Subscription ID and service principles as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. +#Get Subscription ID and resource groups. It is used as default for controller, SQL Server Master instance (sa account) and Knox. # while true; do read -s -p "Your Azure Subscription: " subscription From 8d505bdf16917377d77b47f37b14bc0bda66c7c1 Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Fri, 28 Aug 2020 19:17:53 +0100 Subject: [PATCH 11/16] adjust --- .../deployment/private-aks/scripts/deploy-private-aks.sh | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh index e5a492e4..96ef35ef 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh @@ -5,12 +5,12 @@ #!/bin/bash #Get Subscription ID and resource groups. It is used as default for controller, SQL Server Master instance (sa account) and Knox. # -while true; do - read -s -p "Your Azure Subscription: " subscription +do + read -p "Your Azure Subscription: " subscription echo - read -s -p "Your Resource Group Name: " resourcegroup + read -p "Your Resource Group Name: " resourcegroup echo - read -s -p "In which region you're deploying " region + read -p "In which region you're deploying " region echo done From 5942126b0871330b8b94e1e60ba838cbf9ecb595 Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Fri, 28 Aug 2020 19:26:51 +0100 Subject: [PATCH 12/16] adjustment --- .../deployment/private-aks/README.md | 4 ++-- .../private-aks/scripts/deploy-bdc.sh | 2 +- .../scripts/deploy-private-aks-udr.sh | 22 +++++++++---------- .../private-aks/scripts/deploy-private-aks.sh | 16 +++++++------- 4 files changed, 22 insertions(+), 22 deletions(-) diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/README.md b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md index 15540ee5..33643327 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/README.md +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md @@ -24,7 +24,7 @@ https://docs.microsoft.com/en-us/sql/big-data-cluster/deploy-big-data-tools?view 1. Download the script on the location that you are planning to use for the deployment ``` bash -curl --output setup-bdc.sh https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh +curl --output deploy-private-aks.sh https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh ``` 2. Make the script executable @@ -44,7 +44,7 @@ sudo ./deploy-private-aks.sh 1. Download the script on the location that you are planning to use for the deployment ``` bash -curl --output setup-bdc.sh https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +curl --output deploy-private-aks-udr.sh https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh ``` 2. Make the script executable diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh index 043bc80f..21c5160c 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh @@ -3,7 +3,7 @@ #Get password as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. # while true; do - read -s -p "Create Admin username for Big Data Cluster: " bdcadmin + read -p "Create Admin username for Big Data Cluster: " bdcadmin echo read -s -p "Create Password for Big Data Cluster: " password echo diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh index 0ea137c8..fbe934d3 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh @@ -1,17 +1,17 @@ #!/bin/bash #Get Subscription ID and Azure service principal as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. # -while true; do - read -s -p "Your Azure Subscription: " subscription - echo - read -s -p "Your Resource Group Name: " resourcegroup - echo - read -s -p "In which region you're deploying: " region - echo - read -s -p "Your Azure service principal ID: " sp_id - echo - read -s -p "Your Azure service principal Password: " sp_pwd -done + +read -p "Your Azure Subscription: " subscription +echo +read -p "Your Resource Group Name: " resourcegroup +echo +read -p "In which region you're deploying: " region +echo +read -p "Your Azure service principal ID: " sp_id +echo +read -p "Your Azure service principal Password: " sp_pwd + #Define a set of environment variables to be used in resource creations. export SUBID=$subscription diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh index 96ef35ef..9a87819f 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh @@ -5,14 +5,14 @@ #!/bin/bash #Get Subscription ID and resource groups. It is used as default for controller, SQL Server Master instance (sa account) and Knox. # -do - read -p "Your Azure Subscription: " subscription - echo - read -p "Your Resource Group Name: " resourcegroup - echo - read -p "In which region you're deploying " region - echo -done + +read -p "Your Azure Subscription: " subscription +echo +read -p "Your Resource Group Name: " resourcegroup +echo +read -p "In which region you're deploying: " region +echo + #Define a set of environment variables to be used in resource creations. export SUBID=$subscription From 41f69affa224a626036df2ed3bf2c419f5587a44 Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Fri, 28 Aug 2020 19:46:16 +0100 Subject: [PATCH 13/16] adjustments --- .../deployment/private-aks/README.md | 8 +++++--- .../private-aks/scripts/deploy-private-aks-udr.sh | 9 ++++++--- .../deployment/private-aks/scripts/deploy-private-aks.sh | 2 ++ 3 files changed, 13 insertions(+), 6 deletions(-) diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/README.md b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md index 33643327..791fdad9 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/README.md +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md @@ -4,13 +4,14 @@ This repository contains the scripts that you can use to deploy a BDC cluster in This repository contains 3 bash scripts : - **deploy-private-aks.sh** : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster. + - **deploy-private-aks-udr.sh** : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster and limit egress traffic with UDR ( User-defined Routes ). -- **deploy-bdc.sh** : You can use it to deploy Big Data Clusters ( BDC ) in private deployment mode on private AKS cluster with or without User-defined routes based on your project requirements. +- **deploy-bdc.sh** : You can use it to deploy Big Data Clusters ( BDC ) in private deployment mode on private AKS cluster with or without User-defined routes based on your project requirements. Note : Please use this scripts in the Azure VM which manages your AKS private cluster. ## Prerequisites -You can run those scripts on the following client envionrment with Linux OS or WSL/WSL2. +You can run those scripts on the following client environment with Linux OS or WSL/WSL2. The following table link listed common big data cluster tools and how to install them: @@ -61,10 +62,11 @@ sudo ./deploy-private-aks-udr.sh ### deploy-bdc.sh + 1. Download the script on the location that you are planning to use for the deployment ``` bash -curl --output setup-bdc.sh https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh +curl --output deploy-bdc https://raw.githubusercontent.com/microsoft/sql-server-samples/master/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-bdc.sh ``` 2. Make the script executable diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh index fbe934d3..76c95e2c 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh @@ -2,6 +2,11 @@ #Get Subscription ID and Azure service principal as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. # +## +# You can also create service principal instead of using an existing one +#az ad sp create-for-rbac -n "bdcaks-sp" --skip-assignment +## + read -p "Your Azure Subscription: " subscription echo read -p "Your Resource Group Name: " resourcegroup @@ -101,8 +106,6 @@ az network vnet subnet update -g $RESOURCE_GROUP --vnet-name $VNET_NAME --name $ #Create SP and Assign Permission to Virtual Network -az ad sp create-for-rbac -n "bdcaks-sp" --skip-assignment - export APPID=$sp_id export PASSWORD=$sp_pwd export VNETID=$(az network vnet show -g $RESOURCE_GROUP --name $VNET_NAME --query id -o tsv) @@ -135,4 +138,4 @@ az aks create \ --generate-ssh-keys - +az aks get-credentials -g $RESOURCE_GROUP -n $AKS_NAME diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh index 9a87819f..addb4b21 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks.sh @@ -58,3 +58,5 @@ az aks create \ --node-vm-size Standard_D13_v2 \ --node-count 2 \ --generate-ssh-keys + +az aks get-credentials -g $RESOURCE_GROUP -n $AKS_NAME From f5506455156137c8a7dfbd9634109ea4400a37b9 Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Fri, 28 Aug 2020 19:50:16 +0100 Subject: [PATCH 14/16] update guidance --- .../deployment/private-aks/README.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/README.md b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md index 791fdad9..5dc27b56 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/README.md +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/README.md @@ -1,19 +1,20 @@ -# Deploy BDC in private AKS cluster with User-defined Route (UDR) +# Deploy BDC in private AKS cluster with Advanced Networking (CNI) This repository contains the scripts that you can use to deploy a BDC cluster in Azure Kubernetes Service (AKS) private cluster with advanced networking ( CNI ). This repository contains 3 bash scripts : -- **deploy-private-aks.sh** : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster. +- **deploy-private-aks.sh** : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with AKS private cluster. -- **deploy-private-aks-udr.sh** : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with a private endpoint with AKS private cluster and limit egress traffic with UDR ( User-defined Routes ). -- **deploy-bdc.sh** : You can use it to deploy Big Data Clusters ( BDC ) in private deployment mode on private AKS cluster with or without User-defined routes based on your project requirements. Note : Please use this scripts in the Azure VM which manages your AKS private cluster. +- **deploy-private-aks-udr.sh** : You can use it to deploy private AKS cluster with private endpoint, it fits the use case that you need to deploy BDC with AKS private cluster and limit egress traffic with UDR ( User-defined Routes ). + +- **deploy-bdc.sh** : You can use it to deploy Big Data Clusters ( BDC ) in private deployment mode on private AKS cluster with or without User-defined routes based on your project requirements. **Note** : Please use this scripts in the Azure VM which manages your AKS private cluster. ## Prerequisites You can run those scripts on the following client environment with Linux OS or WSL/WSL2. -The following table link listed common big data cluster tools and how to install them: +The following link listed common big data cluster tools and how to install them: https://docs.microsoft.com/en-us/sql/big-data-cluster/deploy-big-data-tools?view=sql-server-ver15 From f287ebd859b72f327c1af2ca86e343e3ba3cbedf Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Fri, 28 Aug 2020 20:35:39 +0100 Subject: [PATCH 15/16] add scripts --- .../deployment/private-aks/scripts/deploy-private-aks-udr.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh index 76c95e2c..ecce1dc6 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh @@ -65,7 +65,7 @@ az network vnet subnet create \ --resource-group $RESOURCE_GROUP \ --vnet-name $VNET_NAME \ --name AzureFirewallSubnet \ - --address-prefix 10.2.0.0/24 + --address-prefix 10.3.0.0/24 #Create Azure firewall az network firewall create -g $RESOURCE_GROUP -n $FWNAME -l $REGION_NAME --enable-dns-proxy true From 56ff5668f1cc0e33b807465bfa8aaf57445f9d9c Mon Sep 17 00:00:00 2001 From: cloudmelon Date: Fri, 28 Aug 2020 20:40:32 +0100 Subject: [PATCH 16/16] add --- .../private-aks/scripts/deploy-private-aks-udr.sh | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh index ecce1dc6..13fb8085 100644 --- a/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh +++ b/samples/features/sql-big-data-cluster/deployment/private-aks/scripts/deploy-private-aks-udr.sh @@ -1,12 +1,9 @@ #!/bin/bash #Get Subscription ID and Azure service principal as input. It is used as default for controller, SQL Server Master instance (sa account) and Knox. -# - ## -# You can also create service principal instead of using an existing one +#You can also create service principal instead of using an existing one #az ad sp create-for-rbac -n "bdcaks-sp" --skip-assignment -## - +# read -p "Your Azure Subscription: " subscription echo read -p "Your Resource Group Name: " resourcegroup