ECS Amazon Linux 2部署eBPF性能分析代理失败求助
在AWS ECS(Amazon Linux 2主机)部署eBPF性能分析代理时遇到容器启动错误
容器启动错误
CannotStartContainerError: Error response from daemon: failed to create task for container: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: open /proc/sys/net/ipv4/
环境详情
- 主机系统:Amazon Linux 2(最新镜像)
- 容器编排:AWS ECS
- 部署方式:Terraform
尝试过的性能分析方案
Parca Agent
{ "name": "container", "image": "ghcr.io/parca-dev/parca-agent:v0.16.0", "essential": true, "privileged": true, "mountPoints": [ { "sourceVolume": "proc", "containerPath": "/proc", "readOnly": false }, { "sourceVolume": "sys", "containerPath": "/sys", "readOnly": false }, { "sourceVolume": "cgroup", "containerPath": "/sys/fs/cgroup", "readOnly": false }, { "sourceVolume": "hostroot", "containerPath": "/host", "readOnly": true } ], "command": ["--server-address=http://parca-server:7070", "--node", "--threads", "--cpu-time"] }
OpenTelemetry eBPF Profiler
{ "name": "container", "image": "otel/opentelemetry-ebpf-profiler-dev:latest", "essential": true, "privileged": true, "mountPoints": [ { "sourceVolume": "proc", "containerPath": "/proc", "readOnly": false }, { "sourceVolume": "sys", "containerPath": "/sys", "readOnly": false }, { "sourceVolume": "cgroup", "containerPath": "/sys/fs/cgroup", "readOnly": false }, { "sourceVolume": "hostroot", "containerPath": "/host", "readOnly": true } ], "linuxParameters": { "capabilities": { "add": ["ALL"] } } }
无论尝试哪种方案,都会触发上述相同错误。
已尝试的解决措施
- 设置
privileged: true,并以非只读方式挂载/proc、/sys、/sys/fs/cgroup - 在任务定义和服务级别添加全部Linux权限
- 尝试
host、bridge、awsvpc等不同网络模式 - 以root用户(
user: "root"和"0:0")运行容器,禁用no-new-privileges安全选项
咨询问题
- Amazon Linux 2是否存在已知限制,导致即使在特权模式下容器也无法访问
/proc/sys/net/ipv4/? - ECS主机是否需要特定内核参数或配置才能让性能分析代理正常工作?
- 是否有人成功在ECS的Amazon Linux 2主机上运行过基于eBPF的性能分析工具或其他内核级性能分析工具?
注:无法迁移到K8s。
内容的提问来源于stack exchange,提问作者Byron Martinez
相关产品推荐
相关产品推荐

