Azure 中的虚拟机隔离Virtual machine isolation in Azure

Azure 计算提供独立于特定硬件类型并专用于单个客户的虚拟机大小。Azure Compute offers virtual machine sizes that are Isolated to a specific hardware type and dedicated to a single customer. 这些虚拟机大小非常适合于与其他客户的工作负载(涉及符合性和法规要求等元素)高度隔离的工作负载。These virtual machine sizes are best suited for workloads that require a high degree of isolation from other customers for workloads involving elements like compliance and regulatory requirements. 客户还可以选择利用对嵌套虚拟机的 Azure 支持,对这些独立的虚拟机资源进一步细分。Customers can also choose to further subdivide the resources of these Isolated virtual machines by using Azure support for nested virtual machines.

使用独立大小可保证你的虚拟机将是在特定服务器实例上唯一运行的虚拟机。Utilizing an isolated size guarantees that your virtual machine will be the only one running on that specific server instance. 当前的独立虚拟机产品/服务包括:The current Isolated virtual machine offerings include:

  • Standard_E64is_v3Standard_E64is_v3

  • Standard_E64i_v3Standard_E64i_v3

  • Standard_M128msStandard_M128ms

  • Standard_DS15_v2 *Standard_DS15_v2 *

  • Standard_D15_v2 *Standard_D15_v2 *

  • Standard_F72s_v2Standard_F72s_v2

*隔离保证已于 2020 年 5 月 15 日停用*Isolation guarantee will retire by May 15, 2020

D15_v2/DS15_v2 隔离将在 2020 年 5 月 15 日停用Retiring D15_v2/DS15_v2 isolation on May 15, 2020

2020 年 2 月 10 日更新:“隔离”停用时间线已延长到 2020 年 5 月 15 日Update on February 10, 2020: The "isolation" retirement timeline has been extended to May 15, 2020"

Azure 专用主机现在是 GA,使你可在单租户物理服务器上运行组织的 Linux 和 Windows 虚拟机。Azure Dedicated Host is now GA, which allows you to run your organization's Linux and Windows virtual machines on single-tenant physical servers. 我们计划用 Azure 专用主机完全替换隔离的 Azure VM。We plan to fully replace isolated Azure VMs with Azure Dedicated Host. 2020 年 5 月 15 日之后,D15_v2/DS15_v2 Azure VM 将不再是硬件隔离的 VM。After May 15, 2020 the D15_v2/DS15_v2 Azure VMs will no longer be hardware isolated.

这对我有何影响?How does this affect me?

在 2020 年 5 月 15 日之后,我们将不再为你的 D15_v2/DS15_v2 Azure 虚拟机提供隔离保证。After May 15, 2020, we will no longer provide an isolation guarantee for your D15_v2/DS15_v2 Azure virtual machines.

我应该采取什么措施?What actions should I take?

如果对你而言硬件隔离不是必需的,则无需采取任何措施。If hardware isolation is not required for you, there is no action you need to take.

如果对你而言隔离是必需的,则你需要在 2020 年 5 月 15 日之前执行以下任一操作:If isolation is required to you, before May 15, 2020, you would need to either:

• 将你的工作负载迁移到 Azure 专用主机。Migrate your workload to Azure Dedicated Host.

• 将你的工作负载迁移到另一台 Azure 独立虚拟机。Migrate your workload to another Azure isolated virtual machine.


问:D/DS15_v2 大小是否将被停用?Q: Is the size D/DS15_v2 going to get retired?

:否,只有“隔离”功能将被停用。A: No, only "isolation" feature is going to get retired. 如果你不需要隔离,则无需采取任何措施。If you do not need isolation, you do not need to take any action.

问:其他独立大小将于何时停用?Q: When are the other isolated sizes going to retire?

:在官方正式停用这些大小之前,我们将提前 12 个月进行提醒。A: We will provide reminders 12 months in advance of the official decommissioning of the sizes.

问:当我的虚拟机落脚于非隔离的硬件上时,是否会出现停机?Q: Is there a downtime when my vm lands on a non-isolated hardware?

:如果你不需要隔离,则无需采取任何措施,并且你不会看到停机。A: If you do not need isolation, you do not need to take any action and you would not see any downtime.

问:移动到非独立虚拟机是否有任何成本变化?Q: Are there any cost changes for moving to a non-isolated virtual machine?

:否A: No

问:我是依赖于白银或黄金耐久性层级的 Azure Service Fabric 客户。Q: I'm an Azure Service Fabric Customer relying on the Silver or Gold Durability Tiers. 此更改是否会影响我?Does this change impact me?

:否。A: No. Service Fabric 的耐久性层级提供的保证即使在此更改发生后也将继续履行。The guarantees provided by Service Fabric's Durability Tiers will continue to function even after this change. 如果你出于其他原因而需要物理硬件隔离,可能仍需采取上述措施之一。If you require physical hardware isolation for other reasons, you may still need to take one of the actions described above.