AWS EC2 Linux 2023实例启动时UserData超时,手动执行正常
问题:EC2 Linux 2023实例UserData执行AWS CLI命令超时,手动运行正常
在AWS EC2 Linux 2023实例启动阶段执行UserData时,aws ec2 associate-address命令出现超时错误,但手动运行相同命令无报错。启动失败与手动成功期间无网络或其他环境变更。已尝试在UserData中添加5秒、60秒延迟,更换可用区,均未解决。
环境信息
- Linux:Amazon Linux 2023 AMI 2023.6.20241212.0 x86_64 HVM kernel-6.1
- AWS CLI:aws-cli/2.22.26 Python/3.12.6 Linux/6.1.119-129.201.amzn2023.x86_64 exe/x86_64.amzn.2023
- 启动模板元数据设置:V1和V2(令牌可选)
UserData(已添加ping测试)
#!/bin/bash echo "pulling instance ID from instance meta data" INSTANCE_ID=$(curl -s http://169.254.169.254/latest/meta-data/instance-id) echo "" echo "instance ID: "$INSTANCE_ID echo "" # wait for network echo "Wait for ping response from ec2.us-east-2.amazonaws.com" echo "" printf -v date '%(%Y-%m-%d %H:%M:%S)T\n' -1 echo $date while ! ping -c 1 ec2.us-east-2.amazonaws.com &> /dev/null; do echo "Waiting for ping response from ec2.us-east-2.amazonaws.com..." printf -v date '%(%Y-%m-%d %H:%M:%S)T\n' -1 echo $date sleep 1 done echo "" echo "associating elastic IP eipalloc-redacted to instance" aws ec2 associate-address --instance-id $INSTANCE_ID --allocation-id=eipalloc-redacted --allow-reassociation echo "" echo "elastic IP address associated to instance" echo "" echo ""
启动失败日志
2024-12-29 18:12:13,616 - MainThread - botocore.endpoint - DEBUG - Sending http request: <AWSPreparedRequest stream_output=False, method=POST, url=https://ec2.us-east-2.amazonaws.com/, headers={'Content-Type': b'application/x-www-form-urlencoded; charset=utf-8', 'User-Agent': b'aws-cli/2.22.26 md/awscrt#0.23.4 ua/2.0 os/linux#6.1.119-129.201.amzn2023.x86_64 md/arch#x86_64 lang/python#3.12.6 md/pyimpl#CPython cfg/retry-mode#standard md/installer#exe md/distrib#amzn.2023 md/prompt#off md/command#ec2.associate-address', 'X-Amz-Date': b'20241229T181213Z', 'X-Amz-Security-Token': redacted, 'Authorization': b'AWS4-HMAC-SHA256 Credential=redacted/us-east-2/ec2/aws4_request, SignedHeaders=content-type;host;x-amz-date;x-amz-security-token, Signature=redacted', 'Content-Length': '137'}> 2024-12-29 18:12:13,623 - MainThread - botocore.httpsession - DEBUG - Certificate path: /usr/local/aws-cli/v2/2.22.26/dist/awscli/botocore/cacert.pem 2024-12-29 18:12:13,623 - MainThread - urllib3.connectionpool - DEBUG - Starting new HTTPS connection (1): ec2.us-east-2.amazonaws.com:443 2024-12-29 18:13:15,154 - MainThread - botocore.endpoint - DEBUG - Exception received when sending HTTP request. Traceback (most recent call last): File "urllib3/connection.py", line 174, in _new_conn File "urllib3/util/connection.py", line 95, in create_connection File "urllib3/util/connection.py", line 85, in create_connection TimeoutError: timed out
手动执行成功日志
2024-12-29 20:43:11,351 - MainThread - botocore.endpoint - DEBUG - Sending http request: <AWSPreparedRequest stream_output=False, method=POST, url=https://ec2.us-east-2.amazonaws.com/, headers={'Content-Type': b'application/x-www-form-urlencoded; charset=utf-8', 'User-Agent': b'aws-cli/2.22.26 md/awscrt#0.23.4 ua/2.0 os/linux#6.1.119-129.201.amzn2023.x86_64 md/arch#x86_64 lang/python#3.12.6 md/pyimpl#CPython cfg/retry-mode#standard md/installer#exe md/distrib#amzn.2023 md/prompt#off md/command#ec2.associate-address', 'X-Amz-Date': b'20241229T204311Z', 'X-Amz-Security-Token': redacted', 'Authorization': redacted/us-east-2/ec2/aws4_request, SignedHeaders=content-type;host;x-amz-date;x-amz-security-token, Signature=redacted', 'Content-Length': '137'}> 2024-12-29 20:43:11,352 - MainThread - botocore.httpsession - DEBUG - Certificate path: /usr/local/aws-cli/v2/2.22.26/dist/awscli/botocore/cacert.pem 2024-12-29 20:43:11,352 - MainThread - urllib3.connectionpool - DEBUG - Starting new HTTPS connection (1): ec2.us-east-2.amazonaws.com:443 2024-12-29 20:43:12,365 - MainThread - urllib3.connectionpool - DEBUG - https://ec2.us-east-2.amazonaws.com:443 "POST / HTTP/1.1" 200 278 2024-12-29 20:43:12,366 - MainThread - botocore.parsers - DEBUG - Response headers: {'x-amzn-RequestId': 'redacted', 'Cache-Control': 'no-cache, no-store', 'Strict-Transport-Security': 'max-age=31536000; includeSubDomains', 'Content-Type': 'text/xml;charset=UTF-8', 'Content-Length': '278', 'Date': 'Sun, 29 Dec 2024 20:43:11 GMT', 'Server': 'AmazonEC2'} 2024-12-29 20:43:12,366 - MainThread - botocore.parsers - DEBUG - Response body: b'<?xml version="1.0" encoding="UTF-8"?> <AssociateAddressResponse xmlns="http://ec2.amazonaws.com/doc/2016-11-15/"><requestId>redacted</requestId><return>true</return><associationId>eipassoc-redacted</associationId></AssociateAddressResponse>' 2024-12-29 20:43:12,366 - MainThread - botocore.hooks - DEBUG - Event needs-retry.ec2.AssociateAddress: calling handler <bound method RetryHandler.needs_retry of <botocore.retries.standard.RetryHandler object at 0x7fae76a03e90>> 2024-12-29 20:43:12,367 - MainThread - botocore.retries.standard - DEBUG - Not retrying request. 2024-12-29 20:43:12,367 - MainThread - botocore.hooks - DEBUG - Event after-call.ec2.AssociateAddress: calling handler <bound method RetryQuotaChecker.release_retry_quota of <botocore.retries.standard.RetryQuotaChecker object at redacted>> 2024-12-29 20:43:12,367 - MainThread - awscli.formatter - DEBUG - RequestId: redacted { "AssociationId": "eipassoc-redacted" }
EC2实例IAM角色策略
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "ec2:DescribeAddresses", "ec2:AllocateAddress", "ec2:DescribeInstances", "ec2:AssociateAddress", "ec2:DescribeAddressesAttribute", "ec2:DescribeAddressTransfers", "ec2:DisableAddressTransfer", "ec2:DisassociateAddress", "ec2:EnableAddressTransfer" ], "Resource": "*" } ] }
内容的提问来源于stack exchange,提问作者Douglas Hackney
相关产品推荐
相关产品推荐

