ECS任务无法拉取ECR镜像的问题排查与解决求助
ECS任务无法拉取ECR镜像的问题排查与解决求助
各位大佬好,我最近在部署ECS Fargate任务的时候碰到了一个棘手的问题——任务始终拉取不到ECR里的镜像,报错说镜像找不到,已经重试过一次还是失败。有没有小伙伴能帮我分析下问题出在哪,怎么解决呀?
原始错误信息
Cannotpullcontainererror: pull image manifest has been retried 1 time(s): failed to resolve ref {accId}.dkr.ecr.us-east-1.amazonaws.com/test-container:latest: {accId}.dkr.ecr.us-east-1.amazonaws.com/test-container:latest: not found
我的CloudFormation模板
AWSTemplateFormatVersion: '2010-09-09' Description: 'ECS service, cluster, and ECR' Resources: # ECR repository EcrRepository: Type: 'AWS::ECR::Repository' Properties: RepositoryName: 'test-container' # ECS cluster EcsCluster: Type: 'AWS::ECS::Cluster' Properties: ClusterName: 'test' # IAM role for ECS task EcsTaskRole: Type: 'AWS::IAM::Role' Properties: AssumeRolePolicyDocument: Version: 2012-10-17 Statement: - Effect: 'Allow' Principal: Service: - 'ecs-tasks.amazonaws.com' Action: - 'sts:AssumeRole' Path: '/' Policies: - PolicyName: 'test_task_policy' PolicyDocument: Version: 2012-10-17 Statement: - Effect: 'Allow' Action: - 'ecr:*' Resource: '*' - Effect: 'Allow' Action: - 'logs:CreateLogGroup' - 'logs:CreateLogStream' - 'logs:PutLogEvents' Resource: 'arn:aws:logs:*:*:*' - Effect: 'Allow' Action: - 'lambda:InvokeFunction' - 'lambda:GetFunction' Resource: '*' - Effect: 'Allow' Action: - 'ec2:CreateNetworkInterface' - 'ec2:DescribeNetworkInterfaces' - 'ec2:DeleteNetworkInterface' Resource: '*' # ECS task definition EcsTaskDefinition: Type: 'AWS::ECS::TaskDefinition' Properties: Family: 'test' Memory: 512 Cpu: 256 ContainerDefinitions: - Name: 'test_container' Image: !Join [ "", [ !Ref "AWS::AccountId", ".dkr.ecr.", !Ref "AWS::Region", ".amazonaws.com/", !Ref EcrRepository, "" ] ] PortMappings: - ContainerPort: 80 Environment: - Name: 'ENV_VAR_1' Value: 'value1' Essential: true LogConfiguration: LogDriver: awslogs Options: awslogs-group: !Join [ '', [ '/ecs/', !Ref AWS::StackName ] ] awslogs-region: !Ref AWS::Region awslogs-stream-prefix: ecs awslogs-create-group: true TaskRoleArn: !GetAtt EcsTaskRole.Arn ExecutionRoleArn: !GetAtt TestExecutionRole.Arn NetworkMode: awsvpc RequiresCompatibilities: - FARGATE # ECS service EcsService: Type: 'AWS::ECS::Service' Properties: ServiceName: 'test_svc' Cluster: !Ref EcsCluster DesiredCount: 1 TaskDefinition: !Ref EcsTaskDefinition LaunchType: 'FARGATE' NetworkConfiguration: AwsvpcConfiguration: AssignPublicIp: ENABLED SecurityGroups: - !Ref TestSG Subnets: - !Ref TestSubnet TestExecutionRole: Type: AWS::IAM::Role Properties: RoleName: TestExecutionRole AssumeRolePolicyDocument: Version: 2012-10-17 Statement: - Effect: Allow Action: - 'sts:AssumeRole' Principal: Service: - 'ecs-tasks.amazonaws.com' Policies: - PolicyName: EcsTaskExecutionPolicy PolicyDocument: Version: 2012-10-17 Statement: - Effect: Allow Action: - 'ec2:*' - 'ecs:*' - 'logs:*' - 'ecr:*' Resource: '*' # Network TestVPC: Type: AWS::EC2::VPC Properties: CidrBlock: 10.0.0.0/16 EnableDnsSupport: true EnableDnsHostnames: true TestSubnet: Type: AWS::EC2::Subnet Properties: VpcId: !Ref TestVPC CidrBlock: 10.0.0.0/24 MapPublicIpOnLaunch: true TestSG: Type: AWS::EC2::SecurityGroup Properties: GroupDescription: Security group for my ECS task VpcId: !Ref TestVPC SecurityGroupIngress: - IpProtocol: tcp FromPort: 80 ToPort: 80 CidrIp: 0.0.0.0/0 RouteTable: Type: "AWS::EC2::RouteTable" Properties: VpcId: !Ref TestVPC InternetGateway: Type: "AWS::EC2::InternetGateway" VPCGatewayAttachment: Type: "AWS::EC2::VPCGatewayAttachment" Properties: VpcId: !Ref TestVPC InternetGatewayId: !Ref InternetGateway InternetRoute: Type: "AWS::EC2::Route" Properties: DestinationCidrBlock: "0.0.0.0/0" GatewayId: !Ref InternetGateway RouteTableId: !Ref RouteTable SubnetARouteTableAssociation: Type: "AWS::EC2::SubnetRouteTableAssociation" Properties: RouteTableId: !Ref RouteTable SubnetId: !Ref TestSubnet
我自己初步排查的几个方向,但还没找到问题:
- 我确认ECR仓库
test-container已经创建成功,但不确定是不是没有推送latest标签的镜像到这个仓库里?不过我记得之前推过,会不会是标签写错了? - 执行角色
TestExecutionRole已经给了ecr:*的全权限,资源也是*,应该能拉取镜像吧?会不会是信任策略的问题? - 任务定义里的镜像地址是用
!Ref拼接的,应该是正确的账号ID和区域,但会不会拼接出来的地址有问题?比如有没有多余的符号? - 网络方面,Fargate任务已经分配了公网IP,子网也关联了互联网网关,安全组虽然只开了80入站,但出站应该是默认全通的,访问ECR应该没问题吧?
有没有大佬能帮我再梳理下,还有哪些可能的问题点?或者有没有什么我没注意到的细节?
备注:内容来源于stack exchange,提问作者Arthur Luiz
相关产品推荐
相关产品推荐

