You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Batch(Fargate环境)无法拉取ECR镜像的VPC配置排查

AWS Batch(Fargate)从ECR拉取镜像的VPC配置问题

问题描述

运行在Fargate计算环境的AWS Batch Job无法从ECR拉取镜像,报错如下:

CannotPullContainerError: The task cannot pull . There is a connection issue between the task and the registry. Check your task network configuration. : failed to copy: httpReadSeeker: failed open: failed to do request: Get : i/o timeout

当前VPC配置代码:

// Create VPC
this.vpc = new ec2.Vpc(this, `VPC-${props.modelContext}-${props.stageName}`, {
  maxAzs: 3, // Maximum number of Availability Zones to use
  natGateways: 1, // Number of NAT Gateways to use
  subnetConfiguration: [
    {
      subnetType: ec2.SubnetType.PUBLIC,
      name: `PublicSubnet-${props.modelContext}-${props.stageName}`,
    },
    {
      subnetType: ec2.SubnetType.PRIVATE_ISOLATED,
      name: `PrivateSubnet-${props.modelContext}-${props.stageName}`,
    },
  ],
});

// Add VPC endpoint for ECR API
this.ecrApiEndpoint = new ec2.InterfaceVpcEndpoint(
  this,
  `EcrApiEndpoint-${props.modelContext}-${props.stageName}`,
  {
    vpc: this.vpc,
    service: ec2.InterfaceVpcEndpointAwsService.ECR,
  },
);
// Add VPC endpoint for ECR Docker
this.ecrDkrEndpoint = new ec2.InterfaceVpcEndpoint(
  this,
  `EcrDkrEndpoint-${props.modelContext}-${props.stageName}`,
  {
    vpc: this.vpc,
    service: ec2.InterfaceVpcEndpointAwsService.ECR_DOCKER,
  },
);
// Optionally, you can add VPC endpoint for CloudWatch Logs if you're logging in a private subnet
this.cloudwatchLogsEndpoint = new ec2.InterfaceVpcEndpoint(
  this,
  `CloudwatchLogsEndpoint-${props.modelContext}-${props.stageName}`,
  {
    vpc: this.vpc,
    service: ec2.InterfaceVpcEndpointAwsService.CLOUDWATCH_LOGS,
  },
);

this.securityGroup = new ec2.SecurityGroup(this, `SecurityGroup-${props.modelContext}-${props.stageName}`, {
  vpc: this.vpc,
  allowAllOutbound: true,
});

解决配置要点

1. 补全S3网关VPC端点(核心缺失项)

ECR镜像实际存储在S3中,仅配置ECR接口端点无法完成镜像下载,必须添加S3网关端点:

// 添加S3网关VPC端点
this.s3Endpoint = new ec2.GatewayVpcEndpoint(this, `S3Endpoint-${props.modelContext}-${props.stageName}`, {
  vpc: this.vpc,
  service: ec2.GatewayVpcEndpointAwsService.S3,
  subnets: [
    { subnets: this.vpc.isolatedSubnets } // 关联Batch任务所在的隔离私有子网
  ]
});
  • 网关端点无需安全组,但要确保隔离子网的路由表自动添加了指向该端点的路由(目标为com.amazonaws.<你的区域>.s3)。

2. 配置ECR接口端点的安全组入站规则

默认接口端点的安全组拒绝所有入站流量,需添加入站规则允许Batch任务安全组访问443端口:

// 给ECR API端点添加安全组规则
this.ecrApiEndpoint.connections.allowFrom(
  this.securityGroup,
  ec2.Port.tcp(443),
  'Allow Batch task to access ECR API'
);

// 给ECR Docker端点添加安全组规则
this.ecrDkrEndpoint.connections.allowFrom(
  this.securityGroup,
  ec2.Port.tcp(443),
  'Allow Batch task to access ECR Docker registry'
);

3. 确认子网与端点的关联

如果Batch任务运行在PRIVATE_ISOLATED子网,需确保ECR的两个接口端点(ECR、ECR_DOCKER)在该子网有部署:

  • 创建接口端点时,可通过subnets参数手动指定关联的隔离子网,避免默认仅关联公有子网的情况:
    // 创建ECR API端点时指定子网
    this.ecrApiEndpoint = new ec2.InterfaceVpcEndpoint(
      this,
      `EcrApiEndpoint-${props.modelContext}-${props.stageName}`,
      {
        vpc: this.vpc,
        service: ec2.InterfaceVpcEndpointAwsService.ECR,
        subnets: { subnets: this.vpc.isolatedSubnets }
      },
    );
    

4. 验证Batch计算环境的网络配置

  • 确保Batch计算环境指定的子网是包含VPC端点的子网(隔离子网或带NAT的私有子网)。
  • 确认计算环境使用的安全组是你创建的securityGroup,且没有网络ACL限制443端口的进出流量。

内容的提问来源于stack exchange,提问作者jbuddy_13

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 10:44:58