You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署在Fargate上的.NET应用目标组私有IP健康检查失败

问题:.NET Fargate应用公网健康检查正常,但私有IP目标健康检查显示注销中

我正尝试将.NET应用部署在AWS Fargate上,目前通过公网DNS的健康检查可正常通过,但已注册目标的私有IP健康检查失败。请问是否需要在代码或Program.cs中进行配置以允许这类请求通过?

我的Program.cs代码

using CHIPADMINWEB.Extensions;
using Microsoft.AspNetCore.Mvc;

var builder = WebApplication.CreateBuilder(args);
builder.Services.AddHealthChecks();

builder.RegisterServices(typeof(Program));

var isLocalEnv = Environment.GetEnvironmentVariable("IS_LOCAL_ENV");

if (string.IsNullOrEmpty(isLocalEnv) || !isLocalEnv.ToLower().Equals("true"))
{
    builder.Services.AddDataProtection().PersistKeysToAWSSystemsManager("/Backoffice/Frontend/DataProtection");
    builder.Services.AddMvc();
}


var app = builder.Build();

app.MapHealthChecks("/healthz.html").AllowAnonymous();
app.RegisterPipelineComponents(typeof(Program));

Console.WriteLine($"Urls from Program.cs before app.Run(): {string.Join(", ", app.Urls)}");


app.Run("http://*:80");


Console.WriteLine($"Urls from Program.cs afte app.Run(): {string.Join(", ", app.Urls)}");

AWS命令输出

1. aws elbv2 describe-target-groups

{
    "TargetGroups": [
        {
            "TargetGroupArn": "arn:aws:elasticloadbalancing:us-east-1:533267186874:targetgroup/TestSt-testb-R7CTTOEHJ3YZ/edc6b4640fe04145",
            "TargetGroupName": "TestSt-testb-R7CTTOEHJ3YZ",
            "Protocol": "HTTP",
            "Port": 80,
            "VpcId": "vpc-0daab6dbe1f80c361",
            "HealthCheckProtocol": "HTTP",
            "HealthCheckPort": "traffic-port",
            "HealthCheckEnabled": true,
            "HealthCheckIntervalSeconds": 30,
            "HealthCheckTimeoutSeconds": 10,
            "HealthyThresholdCount": 5,
            "UnhealthyThresholdCount": 2,
            "HealthCheckPath": "/healthz.html",
            "Matcher": {
                "HttpCode": "200"
            },
            "LoadBalancerArns": [
                "arn:aws:elasticloadbalancing:us-east-1:533267186874:loadbalancer/app/test-backofficebackend-lb/faa19d4b7637ee2b"
            ],
            "TargetType": "ip",
            "ProtocolVersion": "HTTP1",
            "IpAddressType": "ipv4"
        },
        {
            "TargetGroupArn": "arn:aws:elasticloadbalancing:us-east-1:533267186874:targetgroup/TestSt-testb-YBCCMPDKJYVP/ee7f7b52f9d4fce5",
            "TargetGroupName": "TestSt-testb-YBCCMPDKJYVP",
            "Protocol": "HTTP",
            "Port": 80,
            "VpcId": "vpc-0daab6dbe1f80c361",
            "HealthCheckProtocol": "HTTP",
            "HealthCheckPort": "traffic-port",
            "HealthCheckEnabled": true,
            "HealthCheckIntervalSeconds": 30,
            "HealthCheckTimeoutSeconds": 10,
            "HealthyThresholdCount": 5,
            "UnhealthyThresholdCount": 2,
            "HealthCheckPath": "/healthz.html",
            "Matcher": {
                "HttpCode": "200"
            },
            "LoadBalancerArns": [
                "arn:aws:elasticloadbalancing:us-east-1:533267186874:loadbalancer/app/test-backofficefrontend-lb/6721d13b8aad4bd1"
            ],
            "TargetType": "ip",
            "ProtocolVersion": "HTTP1",
            "IpAddressType": "ipv4"
        },
        {
            "TargetGroupArn": "arn:aws:elasticloadbalancing:us-east-1:533267186874:targetgroup/TestSt-testm-W2PLGYCYO3NA/84e37f2be9769802",
            "TargetGroupName": "TestSt-testm-W2PLGYCYO3NA",
            "Protocol": "HTTP",
            "Port": 80,
            "VpcId": "vpc-0daab6dbe1f80c361",
            "HealthCheckProtocol": "HTTP",
            "HealthCheckPort": "traffic-port",
            "HealthCheckEnabled": true,
            "HealthCheckIntervalSeconds": 30,
            "HealthCheckTimeoutSeconds": 10,
            "HealthyThresholdCount": 5,
            "UnhealthyThresholdCount": 2,
            "HealthCheckPath": "/healthz.html",
            "Matcher": {
                "HttpCode": "200"
            },
            "LoadBalancerArns": [
                "arn:aws:elasticloadbalancing:us-east-1:533267186874:loadbalancer/app/test-mobileappbackend-lb/c85648b4e24646b4"
            ],
            "TargetType": "ip",
            "ProtocolVersion": "HTTP1",
            "IpAddressType": "ipv4"
        }
    ]
}

2. aws elbv2 describe-target-health --target-group-arn arn:aws:elasticloadbalancing:us-east-1:533267186874:targetgroup/TestSt-testb-YBCCMPDKJYVP/ee7f7b52f9d4fce5

{
    "TargetHealthDescriptions": [
        {
            "Target": {
                "Id": "10.0.3.229",
                "Port": 80,
                "AvailabilityZone": "us-east-1b"
            },
            "HealthCheckPort": "80",
            "TargetHealth": {
                "State": "draining",
                "Reason": "Target.DeregistrationInProgress",
                "Description": "Target deregistration is in progress"
            }
        },
        {
            "Target": {
                "Id": "10.0.3.50",
                "Port": 80,
                "AvailabilityZone": "us-east-1b"
            },
            "HealthCheckPort": "80",
            "TargetHealth": {
                "State": "draining",
                "Reason": "Target.DeregistrationInProgress",
                "Description": "Target deregistration is in progress"
            }
        }
    ]
}

解答

代码无需额外配置

你的Program.cs已经正确完成了必要配置:

  • app.MapHealthChecks("/healthz.html").AllowAnonymous();开放了无需认证的健康检查端点,完全匹配目标组的检查要求
  • app.Run("http://*:80");监听了所有网卡的80端口,包括Fargate任务的私有IP,私有IP发起的请求可以正常到达端点

核心问题:目标处于注销流程中

从健康检查输出的State: draining和Reason: Target.DeregistrationInProgress可以明确,这不是健康检查本身失败,而是目标组正在执行注销操作,移除这些Fargate任务实例。

排查与解决步骤

  1. 确认ECS任务状态:
    登录ECS控制台,查看对应服务的任务是否在进行版本更新或停止操作。如果是部署新版本导致旧任务被替换,旧任务进入注销状态是正常流程,等待新任务完成注册即可。

  2. 调整目标组注销延迟:
    如果任务正常运行但长期处于注销状态,可在目标组配置中修改注销延迟(Deregistration delay),建议设置为300秒,给负载均衡器足够时间完成健康检查验证,避免提前终止任务。

  3. 验证VPC网络连通性:

    • 确保Fargate任务的安全组允许来自负载均衡器安全组的80端口入站请求
    • 确保负载均衡器的安全组允许向Fargate任务安全组的80端口出站请求
      公网健康检查正常不代表VPC内部网络连通,需确认私有IP的访问路径无防火墙/安全组拦截。
  4. 检查任务内部健康端点:
    通过CloudWatch查看任务日志,或在任务内部执行curl http://<私有IP>:80/healthz.html,确认端点是否返回200状态码,排除任务内部服务异常的可能。

  5. 确认目标组配置匹配:
    你的目标组健康检查路径、端口、HTTP状态码规则都与代码中的端点一致,配置无问题。


内容的提问来源于stack exchange,提问作者Damien

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 05:50:55