AWS Batch(Fargate环境)无法拉取ECR镜像的VPC配置排查
AWS Batch(Fargate)从ECR拉取镜像的VPC配置问题
问题描述
运行在Fargate计算环境的AWS Batch Job无法从ECR拉取镜像,报错如下:
CannotPullContainerError: The task cannot pull
. There is a connection issue between the task and the registry. Check your task network configuration. : failed to copy: httpReadSeeker: failed open: failed to do request: Get
: i/o timeout
当前VPC配置代码:
// Create VPC this.vpc = new ec2.Vpc(this, `VPC-${props.modelContext}-${props.stageName}`, { maxAzs: 3, // Maximum number of Availability Zones to use natGateways: 1, // Number of NAT Gateways to use subnetConfiguration: [ { subnetType: ec2.SubnetType.PUBLIC, name: `PublicSubnet-${props.modelContext}-${props.stageName}`, }, { subnetType: ec2.SubnetType.PRIVATE_ISOLATED, name: `PrivateSubnet-${props.modelContext}-${props.stageName}`, }, ], }); // Add VPC endpoint for ECR API this.ecrApiEndpoint = new ec2.InterfaceVpcEndpoint( this, `EcrApiEndpoint-${props.modelContext}-${props.stageName}`, { vpc: this.vpc, service: ec2.InterfaceVpcEndpointAwsService.ECR, }, ); // Add VPC endpoint for ECR Docker this.ecrDkrEndpoint = new ec2.InterfaceVpcEndpoint( this, `EcrDkrEndpoint-${props.modelContext}-${props.stageName}`, { vpc: this.vpc, service: ec2.InterfaceVpcEndpointAwsService.ECR_DOCKER, }, ); // Optionally, you can add VPC endpoint for CloudWatch Logs if you're logging in a private subnet this.cloudwatchLogsEndpoint = new ec2.InterfaceVpcEndpoint( this, `CloudwatchLogsEndpoint-${props.modelContext}-${props.stageName}`, { vpc: this.vpc, service: ec2.InterfaceVpcEndpointAwsService.CLOUDWATCH_LOGS, }, ); this.securityGroup = new ec2.SecurityGroup(this, `SecurityGroup-${props.modelContext}-${props.stageName}`, { vpc: this.vpc, allowAllOutbound: true, });
解决配置要点
1. 补全S3网关VPC端点(核心缺失项)
ECR镜像实际存储在S3中,仅配置ECR接口端点无法完成镜像下载,必须添加S3网关端点:
// 添加S3网关VPC端点 this.s3Endpoint = new ec2.GatewayVpcEndpoint(this, `S3Endpoint-${props.modelContext}-${props.stageName}`, { vpc: this.vpc, service: ec2.GatewayVpcEndpointAwsService.S3, subnets: [ { subnets: this.vpc.isolatedSubnets } // 关联Batch任务所在的隔离私有子网 ] });
- 网关端点无需安全组,但要确保隔离子网的路由表自动添加了指向该端点的路由(目标为
com.amazonaws.<你的区域>.s3)。
2. 配置ECR接口端点的安全组入站规则
默认接口端点的安全组拒绝所有入站流量,需添加入站规则允许Batch任务安全组访问443端口:
// 给ECR API端点添加安全组规则 this.ecrApiEndpoint.connections.allowFrom( this.securityGroup, ec2.Port.tcp(443), 'Allow Batch task to access ECR API' ); // 给ECR Docker端点添加安全组规则 this.ecrDkrEndpoint.connections.allowFrom( this.securityGroup, ec2.Port.tcp(443), 'Allow Batch task to access ECR Docker registry' );
3. 确认子网与端点的关联
如果Batch任务运行在PRIVATE_ISOLATED子网,需确保ECR的两个接口端点(ECR、ECR_DOCKER)在该子网有部署:
- 创建接口端点时,可通过
subnets参数手动指定关联的隔离子网,避免默认仅关联公有子网的情况:// 创建ECR API端点时指定子网 this.ecrApiEndpoint = new ec2.InterfaceVpcEndpoint( this, `EcrApiEndpoint-${props.modelContext}-${props.stageName}`, { vpc: this.vpc, service: ec2.InterfaceVpcEndpointAwsService.ECR, subnets: { subnets: this.vpc.isolatedSubnets } }, );
4. 验证Batch计算环境的网络配置
- 确保Batch计算环境指定的子网是包含VPC端点的子网(隔离子网或带NAT的私有子网)。
- 确认计算环境使用的安全组是你创建的
securityGroup,且没有网络ACL限制443端口的进出流量。
内容的提问来源于stack exchange,提问作者jbuddy_13
相关产品推荐
相关产品推荐

