Azure 存储帐户Azure Storage accounts
若要开始管理、加密、编码、分析和流式处理 Azure 中的媒体内容，需要创建媒体服务帐户。To start managing, encrypting, encoding, analyzing, and streaming media content in Azure, you need to create a Media Services account. 创建媒体服务帐户时，需要提供 Azure 存储帐户资源的名称。When creating a Media Services account, you need to supply the name of an Azure Storage account resource. 指定存储帐户会附加到媒体服务帐户。The specified storage account is attached to your Media Services account.
媒体服务帐户和所有关联的存储帐户必须位于同一 Azure 订阅中。The Media Services account and all associated storage accounts must be in the same Azure subscription. 强烈建议在媒体服务帐户所在的位置使用存储帐户，避免额外的延迟和数据出口成本。It's strongly recommended to use storage accounts in the same location as the Media Services account to avoid additional latency and data egress costs.
必须具有一个主存储帐户，并且可以拥有任意数量的与媒体服务帐户关联的辅助存储帐户 。You must have one Primary storage account and you can have any number of Secondary storage accounts associated with your Media Services account. 媒体服务支持常规用途 v2 (GPv2) 或常规用途 v1 (GPv1) 帐户 。Media Services supports General-purpose v2 (GPv2) or General-purpose v1 (GPv1) accounts. 不允许将仅限 Blob 的帐户作为主帐户。Blob only accounts aren't allowed as Primary.
我们建议你使用 GPv2，以便可以利用最新的功能和性能。We recommend that you use GPv2, so you can take advantage of the latest features and performance. 若要了解存储帐户的详细信息，请参阅 Azure 存储帐户概述。To learn more about storage accounts, see Azure Storage account overview.
仅热访问层支持与 Azure 媒体服务配合使用，尽管其他访问层可用于降低未活跃使用的内容的存储成本。Only the hot access tier is supported for use with Azure Media Services, although the other access tiers can be used to reduce storage costs on content that isn't being actively used.
可以为存储帐户选择不同的 SKU。There are different SKUs you can choose for your storage account. 若要通过存储帐户进行试验，请使用
--sku Standard_LRS。If you want to experiment with storage accounts, use
--sku Standard_LRS. 但是，在选取用于生产的 SKU 时，应考虑
--sku Standard_RAGRS，以便通过异地复制确保业务连续性。However, when picking a SKU for production, you should consider
--sku Standard_RAGRS, which provides geographic replication for business continuity.
存储帐户中的资产Assets in a storage account
在不使用媒体服务 API 的情况下，请勿尝试更改媒体服务 SDK 生成的 BLOB 容器内容。Don't attempt to change the contents of blob containers that were generated by the Media Services SDK without using Media Services APIs.
存储端加密Storage side encryption
若要保护静态资产，应通过存储端加密对资产进行加密。To protect your assets at rest, the assets should be encrypted by the storage side encryption. 下表显示了存储端加密在媒体服务 v3 中的工作方式：The following table shows how the storage side encryption works in Media Services v3:
|加密选项Encryption option||说明Description||媒体服务 v3Media Services v3|
|媒体服务存储加密Media Services storage encryption||AES-256 加密，媒体服务管理的密钥。AES-256 encryption, key managed by Media Services.||不支持。1Not supported.1|
|静态数据的存储服务加密Storage service encryption for data at rest||由 Azure 存储提供的服务器端加密，由 Azure 或客户托管的密钥。Server-side encryption offered by Azure Storage, key managed by Azure or by customer.||。Supported.|
|存储客户端加密Storage client-side encryption||由 Azure 存储提供的客户端加密，由 Key Vault 中的客户托管密钥。Client-side encryption offered by Azure storage, key managed by customer in Key Vault.||不支持。Not supported.|
1 在媒体服务 v3 中，仅当资产是使用媒体服务 v2 创建的时才支持存储加密（AES-256 加密）以实现向后兼容性，这意味着 v3 适用于现有存储加密的资产，但不允许创建新资产。1 In Media Services v3, storage encryption (AES-256 encryption) is only supported for backwards compatibility when your assets were created with Media Services v2, which means v3 works with existing storage encrypted assets but won't allow creation of new ones.
存储帐户错误Storage account errors
如果某个媒体服务帐户处于“已断开连接”状态，则表明该帐户不再能够访问一个或多个附加的存储帐户，因为存储访问密钥已更改。The "Disconnected" state for a Media Services account indicates that the account no longer has access to one or more of the attached storage accounts due to a change in storage access keys. 媒体服务需要最新的存储访问密钥才能执行帐户中的许多任务。Up-to-date storage access keys are required by Media Services to perform many tasks in the account.
下面这些主要场景会导致媒体服务帐户无法访问附加的存储帐户。The following are the primary scenarios that would result in a Media Services account not having access to attached storage accounts.
|媒体服务帐户或附加的存储帐户已迁移到单独的订阅。The Media Services account or attached storage account(s) were migrated to separate subscriptions.||迁移存储帐户或媒体服务帐户，使之全都位于同一订阅中。Migrate the storage account(s) or Media Services account so that they're all in the same subscription.|
|媒体服务帐户在使用另一订阅中的附加存储帐户，因为它是支持此功能的早期媒体服务帐户。The Media Services account is using an attached storage account in a different subscription as it was an early Media Services account where this was supported. 所有早期的媒体服务帐户都已转换成新式的基于 Azure 资源管理器的帐户，其状态将为“已断开连接”。All early Media Services accounts were converted to modern Azure Resources Manager based accounts and will have a Disconnected state.||迁移存储帐户或媒体服务帐户，使之全都位于同一订阅中。Migrate the storage account or Media Services account so that they're all in the same subscription.|