App Runner部署FastAPI应用健康检查失败求助
FastAPI应用部署AWS App Runner健康检查失败排查
我通过ECR上的Docker镜像部署FastAPI应用到AWS App Runner,本地Docker容器(绑定0.0.0.0:8080)运行正常,但App Runner部署时因健康检查失败报错。已添加返回200 OK的/health端点并配置了App Runner健康检查规则,但控制台看不到应用启动日志,事件日志显示健康检查失败。
Dockerfile内容
FROM python:3.11-bullseye # Turns off buffering for easier container logging ENV PYTHONUNBUFFERED=1 # Expose port you want your app on ENV PORT=8080 EXPOSE ${PORT} RUN apt update && apt install ffmpeg unzip -y && apt clean ENV APP_HOME /app WORKDIR $APP_HOME # Install production dependencies. COPY requirements.txt . RUN pip install -r requirements.txt --no-cache-dir && pip install hypercorn --no-cache-dir RUN pip install "pydantic[email]" pydantic_settings gdown RUN gdown --fuzzy "<redacted>" RUN unzip tokenizer_model.zip COPY . . RUN adduser -u 5678 --disabled-password --gecos "" appuser && chown -R appuser /app USER appuser CMD exec hypercorn --bind :$PORT --workers 2 app:app
App Runner事件日志
06-13-2024 08:35:27 AM [AppRunner] Successfully pulled your application image from ECR. 06-13-2024 08:35:37 AM [AppRunner] Provisioning instances and deploying image for publicly accessible service. 06-13-2024 08:35:46 AM [AppRunner] Performing health check on protocol `HTTP` [Path: '/health'], [Port: '8080']. 06-13-2024 08:42:00 AM [AppRunner] Health check failed on protocol `HTTP`[Path: '/health'], [Port: '8080']. Check your configured port number. For more information, see the application logs. 06-13-2024 08:42:13 AM [AppRunner] Deployment with ID : abe5baee271644b28f07eda47f100583 failed. Failure reason : Health check failed.
排查建议
- 验证本地容器端点可达性:运行
docker run -p 8080:8080 <你的镜像ID>,执行curl http://localhost:8080/health确认返回200 OK,排除应用本身的端点问题。 - 确认端口监听范围:在本地容器内执行
netstat -tulpn,检查Hypercorn是否监听0.0.0.0:8080而非127.0.0.1:8080——App Runner无法访问容器内部的回环地址。 - 检查应用启动日志:本地运行容器时观察控制台输出,排查是否有依赖缺失、模型文件加载失败等启动报错(App Runner无日志大概率是容器未成功启动就被终止)。
- 调整健康检查参数:App Runner默认的健康检查初始延迟可能不足以让应用完成模型加载等初始化操作,尝试将初始延迟调至60秒以上,同时确认检查路径、端口、协议配置正确。
- 验证用户权限:在本地容器中切换到appuser(
su appuser),手动执行启动命令hypercorn --bind :8080 --workers 2 app:app,检查是否有权限读取应用文件、绑定端口。 - 重新推送镜像:确保ECR中的镜像与本地测试通过的镜像一致,重新构建并推送镜像,避免构建缓存导致的文件缺失问题。
内容的提问来源于stack exchange,提问作者Zohaib Adnan
相关产品推荐
相关产品推荐

