教程:在 Azure Active Directory 域服务(预览版)中创建和使用针对复原能力或地理位置的副本集Tutorial: Create and use replica sets for resiliency or geolocation in Azure Active Directory Domain Services (preview)

若要提高 Azure Active Directory 域服务 (Azure AD DS) 托管域的复原能力,或部署到靠近应用程序的其他地理位置,可以使用副本集。To improve the resiliency of an Azure Active Directory Domain Services (Azure AD DS) managed domain, or deploy to additional geographic locations close to your applications, you can use replica sets. 每个 Azure AD DS 托管域命名空间(如 aaddscontoso.com)都包含一个初始副本集。Every Azure AD DS managed domain namespace, such as aaddscontoso.com, contains one initial replica set. 在其他 Azure 区域中创建附加副本集的功能可为托管域提供地理复原能力。The ability to create additional replica sets in other Azure regions provides geographical resiliency for a managed domain.

可以将副本集添加到支持 Azure AD DS 的任何 Azure 区域中的任何对等互连虚拟网络。You can add a replica set to any peered virtual network in any Azure region that supports Azure AD DS.

副本集是 Azure AD 域服务中的公共预览功能。Replica sets are a public preview feature in Azure AD Domain Services. 请注意对于仍处于预览版的功能所存在的支持差异。Please be aware of the support differences that exist for features still in preview. 有关预览版的详细信息,请参阅 Azure Active Directory 预览版 SLAFor more information about previews, Azure Active Directory Preview SLA.

本教程介绍如何执行下列操作:In this tutorial, you learn how to:

  • 了解虚拟网络要求Understand the virtual network requirements
  • 创建副本集Create a replica set
  • 删除副本集Delete a replica set

如果还没有 Azure 订阅,可以在开始前创建一个帐户If you don't have an Azure subscription, create an account before you begin.

先决条件Prerequisites

需有以下资源和特权才能完成本教程:To complete this tutorial, you need the following resources and privileges:

登录到 Azure 门户Sign in to the Azure portal

在本教程中,使用 Azure 门户创建和管理副本集。In this tutorial, you create and manage replica sets using the Azure portal. 若要开始操作,请登录到 Azure 门户To get started, first sign in to the Azure portal.

网络注意事项Networking considerations

托管副本集的虚拟网络必须能够相互通信。The virtual networks that host replica sets must be able to communicate with each other. 依赖于 Azure AD DS 的应用程序和服务也需要与托管副本集的虚拟网络建立网络连接。Applications and services that depend on Azure AD DS also need network connectivity to the virtual networks hosting the replica sets. 应在所有虚拟网络之间配置 Azure 虚拟网络对等互连,以创建完全的网状网络。Azure virtual network peering should be configured between all virtual networks to create a fully meshed network. 这些对等互连可在副本集之间实现有效的站点内复制。These peerings enable effective intra-site replication between replica sets.

在 Azure AD DS 中使用副本集之前,请查看以下 Azure 虚拟网络要求:Before you can use replica sets in Azure AD DS, review the following Azure virtual network requirements:

  • 避免 IP 地址空间重叠,以便可实现虚拟网络对等互连和路由。Avoid overlapping IP address spaces to allow for virtual network peering and routing.
  • 使用足够的 IP 地址创建子网,以支持你的方案。Create subnets with enough IP addresses to support your scenario.
  • 确保 Azure AD DS 具有自己的子网。Make sure Azure AD DS has its own subnet. 不要与应用程序 VM 和服务共享此虚拟网络子网。Don't share this virtual network subnet with application VMs and services.
  • 对等互连的虚拟网络不是中转性的。Peered virtual networks are NOT transitive.

提示

当你在 Azure 门户中创建副本集时,系统会为你创建虚拟网络之间的网络对等互连。When you create a replica set in the Azure portal, the network peerings between virtual networks is created for you.

如果需要,在 Azure 门户中添加副本集时可以创建虚拟网络和子网。If needed, you can create a virtual network and subnet when you add a replica set in the Azure portal. 或者,可以为副本集选择目标区域中的现有虚拟网络资源,并让系统自动创建对等互连(如果它们尚不存在)。Or, you can choose existing virtual network resources in the destination region for a replica set and let the peerings be created automatically if they don't already exist.

创建副本集Create a replica set

创建托管域(如 aaddscontoso.com)时,将创建初始副本集。When you create a managed domain, such as aaddscontoso.com, an initial replica set is created. 其他副本集共享相同的命名空间和配置。Additional replica sets share the same namespace and configuration. 对 Azure AD DS 进行的更改(包括配置、用户标识和凭据、组、组策略对象、计算机对象以及其他更改)会应用于使用 AD DS 复制的托管域中的所有副本集。Changes to Azure AD DS, including configuration, user identity and credentials, groups, group policy objects, computer objects, and other changes are applied to all replica sets in the managed domain using AD DS replication.

在本教程中,在 Azure 区域中创建与初始 Azure AD DS 副本集不同的附加副本集。In this tutorial, you create an additional replica set in an Azure region different than the initial Azure AD DS replica set.

若要创建附加副本集,请完成以下步骤:To create an additional replica set, complete the following steps:

  1. 在 Azure 门户中,搜索并选择“Azure AD 域服务”。In the Azure portal, search for and select Azure AD Domain Services.

  2. 选择你的托管域,例如 aaddscontoso.comChoose your managed domain, such as aaddscontoso.com.

  3. 在左侧,选择“副本集(预览版)”。On the left-hand side, select Replica sets (preview). 每个托管域在所选区域中都包含一个初始副本集,如以下示例屏幕截图所示:Each managed domain includes one initial replica set in the selected region, as shown in the following example screenshot:

    在 Azure 门户中查看和添加副本集的示例屏幕截图

    若要创建附加副本集,请选择“+ 添加”。To create an additional replica set, select + Add.

  4. 在“添加副本集”窗口,选择目标区域,如“中国北部” 。In the Add a replica set window, select the destination region, such as China North.

    选择目标区域中的虚拟网络(例如 vnet-chinanorth),然后选择子网(如 aadds-subnet )。Select a virtual network in the destination region, such as vnet-chinanorth, then choose a subnet such as aadds-subnet. 如果需要,请选择“新建”以在目标区域中添加虚拟网络,然后选择“管理”以创建 Azure AD DS 的子网 。If needed, choose Create new to add a virtual network in the destination region, then Manage to create a subnet for Azure AD DS.

    如果它们尚不存在,则会在现有托管域的虚拟网络与目标虚拟网络之间自动创建 Azure 虚拟网络对等互连。If they don't already exist, the Azure virtual network peerings are automatically created between your existing managed domain's virtual network and the destination virtual network.

    以下示例屏幕截图显示在“中国北部”中创建新副本集的过程:The following example screenshot shows the process to create a new replica set in China North:

    在 Azure 门户中创建副本集的示例屏幕截图

  5. 准备就绪后,选择“保存”。When ready, select Save.

创建副本集的过程需要一段时间,因为会在目标区域中创建资源。The process to create the replica set takes some time as the resources are created in the destination region. 随后使用 AD DS 复制来复制托管域本身。The managed domain itself is then replicated using AD DS replication.

在部署继续进行时,副本集会报告为“正在预配”,如以下示例屏幕截图所示。The replica set reports as Provisioning as deployment continues, as shown in the following example screenshot. 完成后,副本集显示为“正在运行”。When complete, the replica set shows as Running.

Azure 门户中副本集部署状态的示例屏幕截图

删除副本集Delete a replica set

托管域当前限制为四个副本:初始副本集以及三个附加副本集。A managed domain is currently limited to four replicas - the initial replica set, and three additional replica sets. 如果不再需要副本集,或者要在其他区域中创建副本集,则可以删除不需要的副本集。If you don't need a replica set anymore, or if you want to create a replica set in another region, you can delete unneeded replica sets.

重要

无法删除托管域中的最后一个副本集。You can't delete the last replica set in a managed domain.

若要删除副本集,请完成以下步骤:To delete a replica set, complete the following steps:

  1. 在 Azure 门户中,搜索并选择“Azure AD 域服务”。In the Azure portal, search for and select Azure AD Domain Services.
  2. 选择你的托管域,例如 aaddscontoso.comChoose your managed domain, such as aaddscontoso.com.
  3. 在左侧,选择“副本集(预览版)”。On the left-hand side, select Replica sets (preview). 从副本集列表中,选择要删除的副本集旁的“…”上下文菜单。From the list of replica sets, select the ... context menu next to the replica set you want to delete.
  4. 从上下文菜单中选择“删除”,然后确认要删除的副本集。Select Delete from the context menu, then confirm you want to delete the replica set.

备注

副本集删除可能是一项耗时的操作。Replica set deletion may be a time-consuming operation.

如果不再需要副本集使用的虚拟网络或对等互连,也可以删除这些资源。If you no longer need the virtual network or peering used by the replica set, you can also delete those resources. 确保其他区域中的其他应用程序资源不需要这些网络连接,然后再删除这些连接。Make sure no other application resources in the other region need the network connections before you delete them.

后续步骤Next steps

在本教程中,你了解了如何执行以下操作:In this tutorial, you learned how to:

  • 配置虚拟网络对等互连Configure virtual network peering
  • 在不同的地理区域中创建副本集Create a replica set in a different geographic region
  • 删除副本集Delete a replica set

有关更多概念信息,请了解副本集在 Azure AD DS 中的工作原理。For more conceptual information, learn how replica sets work in Azure AD DS.