CodeBuild跨区域推送Docker镜像至ECR超时失败求助
跨区域ECR镜像推送失败问题
我的构建流程会拉取测试容器和基础镜像用于Docker构建,同区域ECR推送正常,但从us-east-1构建后推送至us-west-1的ECR失败。已经成功登录目标区域ECR,且IAM角色是全局权限,排除权限问题。
buildspec.yml配置
version: 0.2 env: variables: APP_NAME: "config-server" ARTIFACT_REPO: "config-server" ARTIFACT_DOMAIN: "osint" ACCOUNT_ID: "xxxxxxxxxxxx" BUILD_REGION: "us-east-1" ECR_BUILD_REPO: xxxxxxxxxxxx.dkr.ecr.us-east-1.amazonaws.com exported-variables: - CODEBUILD_BUILD_NUMBER - CODEBUILD_BUILD_ID phases: install: on-failure: ABORT commands: - echo "Building software in ${BUILD_REGION}. Publishing images to ${ECR_PUSH_REGION} @ ${ECR_PUSH_REPO}" - java --version - aws --version - mvn --version finally: - echo "Installation complete" pre_build: on-failure: ABORT commands: - echo "Begin pre-build ${CODEBUILD_BUILD_ID}" - echo "Configure Code Artifact ${ARTIFACT_REPO}" - cp pipeline/settings.xml ~/.m2 - echo "Configure ECR" - aws ecr get-login-password --region ${BUILD_REGION} | docker login --username AWS --password-stdin ${ACCOUNT_ID}.dkr.ecr.${BUILD_REGION}.amazonaws.com - docker pull ${ECR_BUILD_REPO}/eclipse-temurin:17-jre-alpine - echo "Done pulling images" build: on-failure: ABORT commands: - echo "Build started ${CODEBUILD_BUILD_ID}" - export CODEARTIFACT_AUTH_TOKEN=`aws codeartifact get-authorization-token --domain ${ARTIFACT_DOMAIN} --domain-owner ${ACCOUNT_ID} --region ${BUILD_REGION} --query authorizationToken --output text` - mvn package deploy --no-transfer-progress - echo "DONE PACKAGE TARGET; `ls -l target`" - echo Building the Docker image... - version=`mvn help:evaluate -Dexpression=project.version -q -DforceStdout` - if [[ ${version} = *'SNAPSHOT'* ]]; then version="${version:0:3}"; fi - export IMAGE_TAG=${ECR_PUSH_REPO}/${APP_NAME}:${version}.${CODEBUILD_BUILD_NUMBER} - echo "IMAGE TAG=${IMAGE_TAG}" - docker build . -t ${IMAGE_TAG} -f pipeline/Dockerfile finally: - echo "Build complete" post_build: commands: - echo "Post Build started ${CODEBUILD_BUILD_ID}" - echo PUBLISHING IMAGES.... - docker images - aws ecr get-login-password --region ${ECR_PUSH_REGION} | docker login --username AWS --password-stdin ${ACCOUNT_ID}.dkr.ecr.${ECR_PUSH_REGION}.amazonaws.com - echo "Logged on to ${ECR_PUSH_REGION} pushing to ${IMAGE_TAG}" - docker push ${IMAGE_TAG} finally: - echo "Post Build completed"
构建日志
[Container] 2024/01/03 19:04:56.476682 Running command export IMAGE_TAG=${ECR_PUSH_REPO}/${APP_NAME}:${version}.${CODEBUILD_BUILD_NUMBER} [Container] 2024/01/03 19:04:56.483331 Running command echo "IMAGE TAG=${IMAGE_TAG}" IMAGE TAG=xxxxxxxxxxxx.dkr.ecr.us-west-1.amazonaws.com/config-server/config-server:1.0.23 [Container] 2024/01/03 19:04:56.489977 Running command docker build . -t ${IMAGE_TAG} -f pipeline/Dockerfile #0 building with "default" instance using docker driver #1 [internal] load build definition from Dockerfile #1 transferring dockerfile: 1.25kB done #1 DONE 0.0s #2 [internal] load .dockerignore #2 transferring context: 2B done #2 DONE 0.0s #3 [internal] load metadata for xxxxxxxxxxxx.dkr.ecr.us-east-1.amazonaws.com/eclipse-temurin:17-jre-alpine #3 DONE 0.0s #4 [ 1/14] FROM xxxxxxxxxxxx.dkr.ecr.us-east-1.amazonaws.com/eclipse-temurin:17-jre-alpine #4 DONE 0.1s #5 [internal] load build context #5 transferring context: 73.22MB 0.5s done #5 DONE 0.5s #6 [ 2/14] RUN apk update && apk add --no-cache shadow && apk add --no-cache bash && apk add openssh #6 0.387 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/main/x86_64/APKINDEX.tar.gz #6 0.468 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/community/x86_64/APKINDEX.tar.gz #6 0.676 v3.18.5-87-g543300ec707 [https://dl-cdn.alpinelinux.org/alpine/v3.18/main] #6 0.676 v3.18.5-88-gdfacf7fe602 [https://dl-cdn.alpinelinux.org/alpine/v3.18/community] #6 0.676 OK: 20070 distinct packages available #6 0.716 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/main/x86_64/APKINDEX.tar.gz #6 0.786 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/community/x86_64/APKINDEX.tar.gz #6 0.973 (1/2) Installing linux-pam (1.5.2-r10) #6 0.986 (2/2) Installing shadow (4.13-r4) #6 1.002 Executing busybox-1.36.1-r5.trigger #6 1.006 OK: 42 MiB in 46 packages #6 1.055 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/main/x86_64/APKINDEX.tar.gz #6 1.135 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/community/x86_64/APKINDEX.tar.gz #6 1.334 OK: 42 MiB in 46 packages #6 1.581 (1/8) Installing openssh-keygen (9.3_p2-r1) #6 1.625 (2/8) Installing libedit (20221030.3.1-r1) #6 1.629 (3/8) Installing openssh-client-common (9.3_p2-r1) #6 1.652 (4/8) Installing openssh-client-default (9.3_p2-r1) #6 1.663 (5/8) Installing openssh-sftp-server (9.3_p2-r1) #6 1.667 (6/8) Installing openssh-server-common (9.3_p2-r1) #6 1.669 (7/8) Installing openssh-server (9.3_p2-r1) #6 1.679 (8/8) Installing openssh (9.3_p2-r1) #6 1.685 Executing busybox-1.36.1-r5.trigger #6 1.689 OK: 48 MiB in 54 packages #6 DONE 2.6s #12 [ 8/14] COPY pipeline/scripts/startServer.sh /opt/config-server/scripts #12 DONE 0.1s #13 [ 9/14] RUN chmod 770 /opt/config-server/scripts/startServer.sh #13 DONE 0.5s #14 [10/14] RUN mkdir -p /opt/config-server/config #14 DONE 0.4s #15 exporting to image #15 exporting layers #15 exporting layers 0.4s done #15 writing image sha256:1cf6188ef7455bc5666a5b08c4dcf67e58599c47249c56ac02c560e44c7df29c done #15 naming to xxxxxxxxxxxx.dkr.ecr.us-west-1.amazonaws.com/config-server/config-server:1.0.23 done #15 DONE 0.4s [Container] 2024/01/03 19:05:04.821650 Running command echo "Build complete" Build complete [Container] 2024/01/03 19:05:04.835218 Phase complete: BUILD State: SUCCEEDED [Container] 2024/01/03 19:05:04.835234 Phase context status code: Message: [Container] 2024/01/03 19:05:04.870408 Entering phase POST_BUILD [Container] 2024/01/03 19:05:04.877788 Running command echo PUBLISHING IMAGES.... PUBLISHING IMAGES.... [Container] 2024/01/03 19:05:04.885122 Running command docker images REPOSITORY TAG IMAGE ID CREATED SIZE xxxxxxxxxxxx.dkr.ecr.us-west-1.amazonaws.com/config-server/config-server 1.0.23 1cf6188ef745 Less than a second ago 334MB [Container] 2024/01/03 19:05:04.911478 Running command aws ecr get-login-password --region ${ECR_PUSH_REGION} | docker login --username AWS --password-stdin ${ACCOUNT_ID}.dkr.ecr.${ECR_PUSH_REGION}.amazonaws.com WARNING! Your password will be stored unencrypted in /root/.docker/config.json. Configure a credential helper to remove this warning. See https://docs.docker.com/engine/reference/commandline/login/#credentials-store Login Succeeded [Container] 2024/01/03 19:05:06.256340 Running command echo "Logged on to ${ECR_PUSH_REGION} pushing to ${IMAGE_TAG}" Logged on to us-west-1 pushing to xxxxxxxxxxxx.dkr.ecr.us-west-1.amazonaws.com/config-server/config-server:1.0.23 [Container] 2024/01/03 19:05:06.263693 Running command docker push ${IMAGE_TAG} The push refers to repository [xxxxxxxxxxxx.dkr.ecr.us-west-1.amazonaws.com/config-server/config-server] 57936ee548d0: Preparing ea843b68ef0d: Preparing ea843b68ef0d: Retrying in 1 second 322f6000e4aa: Retrying in 1 second EOF [Container] 2024/01/03 19:05:57.948539 Command did not exit successfully docker push ${IMAGE_TAG} exit status 1 [Container] 2024/01/03 19:05:57.953478 Running command echo "Post Build completed" Post Build completed [Container] 2024/01/03 19:05:57.965838 Phase complete: POST_BUILD State: FAILED [Container] 2024/01/03 19:05:57.965855 Phase context status code: COMMAND_EXECUTION_ERROR Message: Error while executing command: docker push ${IMAGE_TAG}. Reason: exit status 1
解决方向
确认目标区域ECR仓库存在
跨区域推送不会自动创建ECR仓库,必须提前在us-west-1区域创建config-server/config-server仓库。调整Docker网络超时参数
跨区域网络延迟可能导致推送超时,在docker push前执行以下命令修改Docker配置:echo '{"max-concurrent-uploads": 1, "timeout": 300}' > /root/.docker/config.json减少并发上传数并延长超时时间,提升推送稳定性。
改用ECR跨区域复制
先将镜像推送到us-east-1的ECR仓库,再通过ECR的跨区域复制功能同步到us-west-1。这种方式利用AWS内部网络,比直接跨区域推送更可靠,只需在源ECR仓库配置复制规则即可。检查CodeBuild网络配置
如果CodeBuild运行在VPC内,确认安全组和路由表允许访问us-west-1的ECR服务。可以临时切换到公共网络环境测试,排除VPC网络限制。
内容的提问来源于stack exchange,提问作者B Randall
相关产品推荐
相关产品推荐

