
模型推理服务云原生后端微服务MLOps人工智能【免费下载链接】kserveStandardized Distributed Generative and Predictive AI Inference Platform for Scalable, Multi-Framework Deployment on Kubernetes项目地址https://gitcode.com/gh_mirrors/ks/kserve点击查看免费下载本指南讲解如何在 KServe InferenceService 中通过storageUri从 Azure Blob Storage 加载模型文件既可以使用公共匿名Blob 快速验证也可以为私有 Blob 配置 Azure Service Principal服务主体或 Managed Identity托管标识并通过 Kubernetes Secret 与 ServiceAccount 完成凭证注入。读完本文你将掌握 Azure Blob 模型目录的 URI 规范、私有存储的完整配置链路以及底层 storage-initializer 的下载与凭证注入原理。关联文档docs/samples/storage/azure/README.md本文涉及的凭证注入代码位于 pkg/credentials/azure/azure_secret.go 与 pkg/credentials/service_account_credentials.go实际下载逻辑位于 python/storage/kserve_storage/kserve_storage.py。背景KServe 如何从存储拉取模型当 InferenceService 的spec.predictor中指定了storageUri时KServe 控制器会为 Pod 注入一个 storage-initializer init 容器镜像默认为kserve/storage-initializer:latest见 config/configmap/inferenceservice.yaml 的storageInitializer配置。该容器在正式预测容器启动前把模型从云存储下载到共享卷默认挂载目录/mnt/models中。因此无论使用哪种存储后端核心都是两点storageUri的书写格式必须能被 storage-initializer 正确解析私有存储的凭证必须通过 Secret ServiceAccount 链路注入到 init 容器。Azure 相关的解析与下载全部集中在python/storage模块即 storage-initializer 的 Python 实现中本文后续会结合其源码逐条印证。使用公共 Azure Blob匿名访问如果模型所在的 Blob 容器允许匿名读取KServe 默认使用匿名客户端下载无需任何凭证配置。只需把storageUri指向 Azure Blob Storage 即可URI 格式如下https://{$STORAGE_ACCOUNT_NAME}.blob.core.windows.net/{$CONTAINER}/{$PATH}官方文档给出的示例https://kserve.blob.core.windows.net/triton/simple_string/对应到 storage-initializer 源码python/storage/kserve_storage/kserve_storage.py 中定义了两组 Azure URI 正则Blob_AZURE_BLOB_REhttps://(.?).blob.core.windows.net/(.)与https://(.?).z[0-9]{1,2}.blob.storage.azure.net/(.)后者对应 Azure 在中国等区域的 z 编号端点File Share_AZURE_FILE_REhttps://(.?).file.core.windows.net/(.)与https://(.?).z[0-9]{1,2}.file.storage.azure.net/(.)。当_get_azure_storage_token()与_get_azure_storage_access_key()都拿不到凭证时下载逻辑会记录Azure credentials or shared access signature token not found, retrying anonymous access并回退到匿名访问这与文档“默认使用匿名客户端”的描述一致。使用私有 BlobAzure Service Principal 认证对于私有容器KServe 支持使用 Azure Service PrincipalSP进行认证。完整流程分三步创建并授权 SP、把 SP 凭据写入 Kubernetes Secret、把 Secret 挂到 ServiceAccount。第一步创建并授权 Service Principal使用 Azure CLI 创建一个 SP也可选择创建用户分配的 Managed Identity 代替 SP流程类似在 Blob 上为 SP 或 Managed Identity 授予Storage Blob Data Owner角色。这一步是必需的KServe 在下载前需要list列出Blob 路径下的内容以过滤出实际要下载的模型文件。从 python/storage/kserve_storage/kserve_storage.py 的_download_azure_blob_async可以看到代码通过container_client.list_blobs(name_starts_withprefix)先按前缀列出全部 Blob再逐个下载因此仅有读取权限Storage Blob Data Reader而不具备列表权限会导致下载失败源码注释也明确写道# note the SP must have Storage Blob Data Owner perms for this to work。第二步把 SP 凭据存为 Kubernetes Secret将 SP 的四个字段写入一个 Opaque 类型的 Secret示例命名为azcredsapiVersion: v1 kind: Secret metadata: name: azcreds type: Opaque data: AZURE_CLIENT_ID: xxxxx AZURE_CLIENT_SECRET: xxxxx AZURE_SUBSCRIPTION_ID: xxxxx AZURE_TENANT_ID: xxxxx注意事项当使用 Managed Identity 时AZURE_CLIENT_SECRET不是必需的凭证由 Azure 侧代管Secret 的四个键名AZURE_CLIENT_ID、AZURE_CLIENT_SECRET、AZURE_SUBSCRIPTION_ID、AZURE_TENANT_ID与 pkg/credentials/azure/azure_secret.go 中定义的常量一一对应同时还兼容历史遗留键名AZ_SUBSCRIPTION_ID、AZ_TENANT_ID、AZ_CLIENT_ID、AZ_CLIENT_SECRET见该文件中的Legacy*常量与legacyAzureEnvKeyMappings映射KServe 实际查找的 Azure Secret 名称可以通过编辑inferenceservice-configConfigMap 进行调整文档中使用的命名空间为kserving-system而当前仓库安装清单中该 ConfigMap 位于kserve命名空间请以你实际安装的命名空间为准kubectl edit -n kserve inferenceservice-config第三步把 Secret 附加到 ServiceAccountKServe 的凭证注入是从 ServiceAccount 的 secret 列表中读取的控制器获取 ServiceAccount 后遍历其secrets字段对每个 Secret 调用mountSecretCredential若检测到 Azure 键则把环境变量注入 init 容器实现见 pkg/credentials/service_account_credentials.go 的CreateSecretVolumeAndEnvFromServiceAccount与mountSecretCredential。默认情况下 KServe 使用名为default的 ServiceAccount你也可以创建自定义 ServiceAccount并在InferenceServiceCRD 上通过serviceAccountName覆盖。示例apiVersion: v1 kind: ServiceAccount metadata: name: sa secrets: - name: azcreds保存上述 YAMLSecret ServiceAccount并应用到集群kubectl apply -f azcreds.yaml关键提示目录 URI 必须以/结尾要引用模型所在的目录而非单个文件storageUri必须以/结尾例如https://accountname.blob.core.windows.net/container/models/iris/v1.1/原因可以从下载逻辑反推_parse_azure_uri会把path拆成container与prefix两部分list_blobs(name_starts_withprefix)以该前缀列出所有 Blob若不带结尾/前缀会匹配到同名的其他对象且下载时会用blob.name.replace(prefix, , 1)计算相对路径目录写法才能正确还原目录层级结构。这也是文档特别强调“must reference the folder where its located with an ending/”的原因。在 InferenceService 中使用 Pod IdentityManaged Identity除了把 SP 凭据写进 Secret你还可以把 Managed Identity 直接指派给 InferenceService 资源即通过 AAD Pod Identity 注入 Azure 身份。做法是在 InferenceService 上添加aadpodidbinding标签标签值对应你预先配置好的 Pod Identity 选择器。完整示例沿用文档中的 tensorflow 预测器 自定义 ServiceAccount--- apiVersion: serving.kserve.io/v1beta1 kind: InferenceService metadata: name: kserve-simple-string labels: aadpodidbinding: piselector spec: template: metadata: predictor: serviceAccountName: sa tensorflow: storageUri: https://kserve.blob.core.windows.net/triton/simple_string/注意上述 YAML 中spec.template一节在官方文档示例中仅为占位其缩进与predictor处于同一层级之外实际使用时请移除占位或按 KServe InferenceService 的字段规范书写predictor是spec的直接子字段。凭证注入的底层实现环境变量如何生成从 Go 侧看当 Secret 中含有 Azure 键时控制器会调用azure.BuildSecretEnvs(secret)见 pkg/credentials/azure/azure_secret.go生成一组corev1.EnvVar每个环境变量都通过SecretKeyRef指向 Secret 中的对应键。可识别的 Azure 环境变量全集AzureEnvKeys包括环境变量用途AZURE_SUBSCRIPTION_IDAzure 订阅 IDAZURE_TENANT_IDAzure AD 租户 IDAZURE_CLIENT_ID应用SP客户端 IDAZURE_CLIENT_SECRETSP 客户端密钥Managed Identity 场景可省略AZURE_STORAGE_ACCESS_KEY存储账号访问密钥走密钥认证时使用AZURE_ACCESS_TOKEN已获取的访问令牌AZURE_ACCESS_EXPIRES_ON_SECONDS访问令牌过期时间戳AZURE_ACCOUNT_NAME存储账号名AZURE_SERVICE_URLAzure 服务 URL除上述以AZURE_开头的键外AZ_*前缀的旧键仍被保留用于向后兼容见LegacyAzureEnvKeysBuildSecretEnvs在读取时会优先做新旧键的映射转换。在 Python 侧storage-initializer 运行环境python/storage/README.md 记录了完整的可用环境变量除了上面与 Go 侧对应的凭据键外还包括两个控制下载并发的调优参数AZURE_MAX_FILE_CONCURRENCY并行下载的文件数Blob 专用默认4AZURE_MAX_CHUNK_CONCURRENCY单个文件内并行下载的 chunk 数Blob 专用默认4。对应的默认值定义在 python/storage/kserve_storage/kserve_storage.py 顶部_AZURE_MAX_FILE_CONCURRENCY/_AZURE_MAX_CHUNK_CONCURRENCY。下载实现使用双层信号量asyncio.Semaphore控制并发并通过download_blob(max_concurrency...)stream.chunks()分块流式写入磁盘避免大模型一次性载入内存。身份解析顺序与认证方式在 python/storage/kserve_storage/kserve_storage.py 的_download_azure_blob_async中凭证的解析顺序是Storage._get_azure_storage_token()先读取AZ_TENANT_ID/AZ_CLIENT_ID/AZ_CLIENT_SECRET旧键并自动转换为AZURE_*新键兼容 Azure SDK 约定随后基于AZURE_CLIENT_ID通过azure.identity.DefaultAzureCredential获取 token credential——这也意味着只要 Pod 环境具备AZURE_CLIENT_ID即可走 SDK 默认的 SP / Managed Identity 链路Storage._get_azure_storage_access_key()回退读取AZURE_STORAGE_ACCESS_KEY使用账号密钥认证两者皆无时记录告警并回退匿名访问。此外_download_azure_file_share分支对应*.file.core.windows.net的 Azure Files使用AZURE_STORAGE_ACCESS_KEY通过ShareServiceClient遍历目录与文件下载支持目录嵌套遍历最大深度 5 层文件数限制由代码中的max_depth控制。补充用 Python SDK 客户端配置 Azure 凭证仓库中的 KServe Python SDKpython/kserve也提供了 Azure 凭证的一键配置能力在 python/kserve/kserve/api/kserve_client.py 中当storage_type azure时调用set_azure_credentials默认凭证文件路径为~/.azure/azure_credentials.json定义于 python/kserve/kserve/constants/constants.py 的AZ_DEFAULT_CREDS_FILE。该函数见 python/kserve/kserve/api/creds_utils.py读取 JSON 中的clientId/clientSecret/subscriptionId/tenantId自动创建 Secret 并绑定到 ServiceAccount等价于手工执行上文第二步与第三步适合在自动化脚本中复用。常见问题与排查要点模型下载失败、提示无权限优先确认 SP / Managed Identity 是否已被授予Storage Blob Data Owner角色因为 KServe 需要listBlob 内容做过滤仅有读权限是不够的URI 指向文件而非目录模型目录必须以/结尾否则前缀解析会错位可能匹配不到任何 Blob下载代码在列表为空时会抛出Failed to fetch model. No model found in %s认证回退到匿名日志中出现retrying anonymous access说明环境变量AZURE_CLIENT_ID/AZURE_STORAGE_ACCESS_KEY均未注入请检查 Secret 是否已附加到serviceAccountName对应的 ServiceAccount以及 Secret 键名是否与上文表格一致注意新旧AZ_*/AZURE_*键的兼容关系Secret 命名空间Secret、ServiceAccount 与 InferenceService 必须位于同一命名空间控制器使用namespace参数读取三者。小结在 KServe 中使用 Azure Blob 承载模型本质上只需掌握两件事URI 规范https://{account}.blob.core.windows.net/{container}/{path}/目录必须以/结尾和凭证注入链路SP/MI 授权 → Secret → ServiceAccount → init 容器环境变量。公共 Blob 开箱即用私有 Blob 则按“创建 SP → 授予 Storage Blob Data Owner → 写入 Secret → 挂载 ServiceAccount”四步配置即可。本文同时结合了 pkg/credentials/azure/azure_secret.go、pkg/credentials/service_account_credentials.go 与 python/storage/kserve_storage/kserve_storage.py 的源码实现帮助你在遇到认证或下载问题时能快速定位到具体环节。赞分享模型推理服务云原生后端微服务MLOps人工智能【免费下载链接】kserveStandardized Distributed Generative and Predictive AI Inference Platform for Scalable, Multi-Framework Deployment on Kubernetes项目地址https://gitcode.com/gh_mirrors/ks/kserve点击查看免费下载相关推荐agentic-awesome-skills 中的 azure-storage-blob-rust用 Rust 操作 Azure Blob Storage 的完整实战指南agentic awesome skills 中的 azure storage blob rust用 Rust 操作 Azure Blob Storage 的AI 技能AI 插件Airbyte 的 legacy-task-load-azure-blob-storage 工具包面向 Azure Blob Storage 的旧版任务加载架构解析Airbyte 的 legacy task load azure blob storage 工具包面向 Azure Blob Storage 的旧版任务加载架数据工程数据集成ETL后端大数据Backstage Azure Blob Storage 集成Locations 配置与 Catalog 实体加载指南Backstage Azure Blob Storage 集成Locations 配置与 Catalog 实体加载指南 本文是 Backstage 中 Azu开发者门户后端前端上一篇RapidOCR 安装教程5 分钟跑通本地 OCR 文字识别下一篇gh_mirrors/to/tools中的决策支持系统创作声明:本文部分内容由AI辅助生成(AIGC),仅供参考