You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ECS(EC2)部署Data-Prepper容器:Parameter Store密钥挂载失败排查

问题分析与解决方案

你的核心问题是错误使用ECS Host Volume引用Parameter Store参数,同时挂载路径、权限配置存在问题,导致Data-Prepper容器启动失败触发部署熔断。以下是具体问题点和修正方案:

存在的问题

  • Volume类型错误:ECS的host类型Volume仅能指向EC2主机本地文件路径,无法直接引用Parameter Store的ARN,需用Secrets Volume将参数内容挂载为容器内文件。
  • 挂载路径不匹配:
    • 原Docker Compose是将配置文件挂载为/usr/share/data-prepper/pipelines/pipelines.yaml,但你现在挂载到目录/usr/share/data-prepper/pipelines,会覆盖整个目录导致容器找不到正确配置。
    • 主配置文件的挂载路径应为/usr/share/data-prepper/config/data-prepper-config.yaml,而非根目录下的同名文件。
  • 权限缺失:任务执行角色(executionRoleArn)未配置Parameter Store访问权限,无法拉取参数内容。
  • 冗余配置:secrets字段是将参数注入为环境变量,与你需要的文件挂载需求冲突,属于冗余配置。
  • 镜像版本不一致:原Docker Compose使用固定版本opensearchproject/data-prepper:2,任务定义用latest可能引发兼容性问题,建议固定版本。

修正后的任务定义

{
    "taskDefinitionArn": "",
    "containerDefinitions": [
        {
            "name": "data-prepper",
            "image": "opensearchproject/data-prepper:2",
            "cpu": 0,
            "portMappings": [
                {
                    "containerPort": 21890,
                    "hostPort": 21890,
                    "protocol": "tcp"
                }
            ],
            "essential": true,
            "environment": [],
            "mountPoints": [
                {
                    "sourceVolume": "pipelines-volume",
                    "containerPath": "/usr/share/data-prepper/pipelines/pipelines.yaml",
                    "readOnly": true
                },
                {
                    "sourceVolume": "config-volume",
                    "containerPath": "/usr/share/data-prepper/config/data-prepper-config.yaml",
                    "readOnly": true
                },
                {
                    "sourceVolume": "root-ca-volume",
                    "containerPath": "/usr/share/data-prepper/root-ca.pem",
                    "readOnly": true
                }
            ],
            "volumesFrom": [],
            "logConfiguration": {
                "logDriver": "awslogs",
                "options": {
                    "awslogs-create-group": "true",
                    "awslogs-group": "/ecs/data-prepper",
                    "awslogs-region": "us-east-2",
                    "awslogs-stream-prefix": "ecs"
                }
            },
            "systemControls": []
        }
    ],
    "family": "data-prepper",
    "taskRoleArn": "<你的任务角色ARN>",
    "executionRoleArn": "<你的执行角色ARN>",
    "networkMode": "host",
    "revision": 9,
    "volumes": [
        {
            "name": "pipelines-volume",
            "secret": {
                "secretArn": "<你的pipelines.yaml参数ARN>"
            }
        },
        {
            "name": "config-volume",
            "secret": {
                "secretArn": "<你的data-prepper-config.yaml参数ARN>"
            }
        },
        {
            "name": "root-ca-volume",
            "secret": {
                "secretArn": "<你的root-ca.pem参数ARN>"
            }
        }
    ]
}

额外配置要求

  1. 执行角色权限:给executionRoleArn对应的IAM角色添加以下权限策略,确保能拉取Parameter Store参数:
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "ssm:GetParameter",
                "ssm:GetParameters"
            ],
            "Resource": [
                "<你的pipelines.yaml参数ARN>",
                "<你的data-prepper-config.yaml参数ARN>",
                "<你的root-ca.pem参数ARN>"
            ]
        }
    ]
}
  1. 参数存储格式:确保Parameter Store中的参数内容是完整的YAML/文件内容,参数类型为String(内容超过4KB则改用StringList或Secrets Manager)。
  2. 日志排查:若部署后仍有问题,查看CloudWatch日志组/ecs/data-prepper中的容器启动日志,确认具体配置错误或文件缺失信息。

内容的提问来源于stack exchange,提问作者Snaps

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 07:36:06