You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CodeBuild跨区域推送Docker镜像至ECR超时失败求助

跨区域ECR镜像推送失败问题

我的构建流程会拉取测试容器和基础镜像用于Docker构建,同区域ECR推送正常,但从us-east-1构建后推送至us-west-1的ECR失败。已经成功登录目标区域ECR,且IAM角色是全局权限,排除权限问题。

buildspec.yml配置

version: 0.2

env:
  variables:
    APP_NAME: "config-server"
    ARTIFACT_REPO: "config-server"
    ARTIFACT_DOMAIN: "osint"
    ACCOUNT_ID: "xxxxxxxxxxxx"
    BUILD_REGION: "us-east-1"
    ECR_BUILD_REPO: xxxxxxxxxxxx.dkr.ecr.us-east-1.amazonaws.com
  exported-variables:
    - CODEBUILD_BUILD_NUMBER
    - CODEBUILD_BUILD_ID
phases:
  install:
    on-failure: ABORT
    commands:
      - echo "Building software in ${BUILD_REGION}. Publishing images to ${ECR_PUSH_REGION} @ ${ECR_PUSH_REPO}"
      - java --version
      - aws --version
      - mvn --version
    finally:
      - echo "Installation complete"
  pre_build:
    on-failure: ABORT
    commands:
      - echo "Begin pre-build ${CODEBUILD_BUILD_ID}"
      - echo "Configure Code Artifact ${ARTIFACT_REPO}"
      - cp pipeline/settings.xml ~/.m2
      - echo "Configure ECR"
      - aws ecr get-login-password --region ${BUILD_REGION} | docker login --username AWS --password-stdin ${ACCOUNT_ID}.dkr.ecr.${BUILD_REGION}.amazonaws.com
      - docker pull ${ECR_BUILD_REPO}/eclipse-temurin:17-jre-alpine
      - echo "Done pulling images"
  build:
    on-failure: ABORT
    commands:
      - echo "Build started ${CODEBUILD_BUILD_ID}"
      - export CODEARTIFACT_AUTH_TOKEN=`aws codeartifact get-authorization-token --domain ${ARTIFACT_DOMAIN} --domain-owner ${ACCOUNT_ID} --region ${BUILD_REGION} --query authorizationToken --output text`
      - mvn package deploy --no-transfer-progress
      - echo "DONE PACKAGE TARGET; `ls -l target`"
      - echo Building the Docker image...
      - version=`mvn help:evaluate -Dexpression=project.version -q -DforceStdout`
      - if [[ ${version} = *'SNAPSHOT'* ]]; then version="${version:0:3}";  fi
      - export IMAGE_TAG=${ECR_PUSH_REPO}/${APP_NAME}:${version}.${CODEBUILD_BUILD_NUMBER}
      - echo "IMAGE TAG=${IMAGE_TAG}"
      - docker build . -t ${IMAGE_TAG} -f pipeline/Dockerfile
    finally:
      - echo "Build complete"
  post_build:
    commands:
      - echo "Post Build started ${CODEBUILD_BUILD_ID}"
      - echo PUBLISHING IMAGES....
      - docker images
      - aws ecr get-login-password --region ${ECR_PUSH_REGION} | docker login --username AWS --password-stdin ${ACCOUNT_ID}.dkr.ecr.${ECR_PUSH_REGION}.amazonaws.com
      - echo "Logged on to ${ECR_PUSH_REGION} pushing to ${IMAGE_TAG}"
      - docker push ${IMAGE_TAG}
    finally:
      - echo "Post Build completed"

构建日志

[Container] 2024/01/03 19:04:56.476682 Running command export IMAGE_TAG=${ECR_PUSH_REPO}/${APP_NAME}:${version}.${CODEBUILD_BUILD_NUMBER}

[Container] 2024/01/03 19:04:56.483331 Running command echo "IMAGE TAG=${IMAGE_TAG}"
IMAGE TAG=xxxxxxxxxxxx.dkr.ecr.us-west-1.amazonaws.com/config-server/config-server:1.0.23

[Container] 2024/01/03 19:04:56.489977 Running command docker build . -t ${IMAGE_TAG} -f pipeline/Dockerfile
#0 building with "default" instance using docker driver

#1 [internal] load build definition from Dockerfile
#1 transferring dockerfile: 1.25kB done
#1 DONE 0.0s

#2 [internal] load .dockerignore
#2 transferring context: 2B done
#2 DONE 0.0s

#3 [internal] load metadata for xxxxxxxxxxxx.dkr.ecr.us-east-1.amazonaws.com/eclipse-temurin:17-jre-alpine
#3 DONE 0.0s

#4 [ 1/14] FROM xxxxxxxxxxxx.dkr.ecr.us-east-1.amazonaws.com/eclipse-temurin:17-jre-alpine
#4 DONE 0.1s

#5 [internal] load build context
#5 transferring context: 73.22MB 0.5s done
#5 DONE 0.5s

#6 [ 2/14] RUN apk update &&     apk add --no-cache shadow &&     apk add --no-cache bash  &&     apk add openssh
#6 0.387 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/main/x86_64/APKINDEX.tar.gz
#6 0.468 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/community/x86_64/APKINDEX.tar.gz
#6 0.676 v3.18.5-87-g543300ec707 [https://dl-cdn.alpinelinux.org/alpine/v3.18/main]
#6 0.676 v3.18.5-88-gdfacf7fe602 [https://dl-cdn.alpinelinux.org/alpine/v3.18/community]
#6 0.676 OK: 20070 distinct packages available
#6 0.716 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/main/x86_64/APKINDEX.tar.gz
#6 0.786 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/community/x86_64/APKINDEX.tar.gz
#6 0.973 (1/2) Installing linux-pam (1.5.2-r10)
#6 0.986 (2/2) Installing shadow (4.13-r4)
#6 1.002 Executing busybox-1.36.1-r5.trigger
#6 1.006 OK: 42 MiB in 46 packages
#6 1.055 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/main/x86_64/APKINDEX.tar.gz
#6 1.135 fetch https://dl-cdn.alpinelinux.org/alpine/v3.18/community/x86_64/APKINDEX.tar.gz
#6 1.334 OK: 42 MiB in 46 packages
#6 1.581 (1/8) Installing openssh-keygen (9.3_p2-r1)
#6 1.625 (2/8) Installing libedit (20221030.3.1-r1)
#6 1.629 (3/8) Installing openssh-client-common (9.3_p2-r1)
#6 1.652 (4/8) Installing openssh-client-default (9.3_p2-r1)
#6 1.663 (5/8) Installing openssh-sftp-server (9.3_p2-r1)
#6 1.667 (6/8) Installing openssh-server-common (9.3_p2-r1)
#6 1.669 (7/8) Installing openssh-server (9.3_p2-r1)
#6 1.679 (8/8) Installing openssh (9.3_p2-r1)
#6 1.685 Executing busybox-1.36.1-r5.trigger
#6 1.689 OK: 48 MiB in 54 packages
#6 DONE 2.6s

#12 [ 8/14] COPY pipeline/scripts/startServer.sh /opt/config-server/scripts
#12 DONE 0.1s

#13 [ 9/14] RUN chmod 770 /opt/config-server/scripts/startServer.sh
#13 DONE 0.5s

#14 [10/14] RUN mkdir -p /opt/config-server/config
#14 DONE 0.4s

#15 exporting to image
#15 exporting layers
#15 exporting layers 0.4s done
#15 writing image sha256:1cf6188ef7455bc5666a5b08c4dcf67e58599c47249c56ac02c560e44c7df29c done
#15 naming to xxxxxxxxxxxx.dkr.ecr.us-west-1.amazonaws.com/config-server/config-server:1.0.23 done
#15 DONE 0.4s

[Container] 2024/01/03 19:05:04.821650 Running command echo "Build complete"
Build complete

[Container] 2024/01/03 19:05:04.835218 Phase complete: BUILD State: SUCCEEDED
[Container] 2024/01/03 19:05:04.835234 Phase context status code:  Message: 
[Container] 2024/01/03 19:05:04.870408 Entering phase POST_BUILD

[Container] 2024/01/03 19:05:04.877788 Running command echo PUBLISHING IMAGES....
PUBLISHING IMAGES....

[Container] 2024/01/03 19:05:04.885122 Running command docker images
REPOSITORY                                                                                                     TAG                           IMAGE ID       CREATED                  SIZE
xxxxxxxxxxxx.dkr.ecr.us-west-1.amazonaws.com/config-server/config-server                                       1.0.23                        1cf6188ef745   Less than a second ago   334MB

[Container] 2024/01/03 19:05:04.911478 Running command aws ecr get-login-password --region ${ECR_PUSH_REGION} | docker login --username AWS --password-stdin ${ACCOUNT_ID}.dkr.ecr.${ECR_PUSH_REGION}.amazonaws.com
WARNING! Your password will be stored unencrypted in /root/.docker/config.json.
Configure a credential helper to remove this warning. See
https://docs.docker.com/engine/reference/commandline/login/#credentials-store

Login Succeeded

[Container] 2024/01/03 19:05:06.256340 Running command echo "Logged on to ${ECR_PUSH_REGION} pushing to ${IMAGE_TAG}"
Logged on to us-west-1 pushing to xxxxxxxxxxxx.dkr.ecr.us-west-1.amazonaws.com/config-server/config-server:1.0.23

[Container] 2024/01/03 19:05:06.263693 Running command docker push ${IMAGE_TAG}
The push refers to repository [xxxxxxxxxxxx.dkr.ecr.us-west-1.amazonaws.com/config-server/config-server]
57936ee548d0: Preparing
ea843b68ef0d: Preparing
ea843b68ef0d: Retrying in 1 second
322f6000e4aa: Retrying in 1 second
EOF

[Container] 2024/01/03 19:05:57.948539 Command did not exit successfully docker push ${IMAGE_TAG} exit status 1
[Container] 2024/01/03 19:05:57.953478 Running command echo "Post Build completed"
Post Build completed

[Container] 2024/01/03 19:05:57.965838 Phase complete: POST_BUILD State: FAILED
[Container] 2024/01/03 19:05:57.965855 Phase context status code: COMMAND_EXECUTION_ERROR Message: Error while executing command: docker push ${IMAGE_TAG}. Reason: exit status 1

解决方向

  1. 确认目标区域ECR仓库存在
    跨区域推送不会自动创建ECR仓库,必须提前在us-west-1区域创建config-server/config-server仓库。

  2. 调整Docker网络超时参数
    跨区域网络延迟可能导致推送超时,在docker push前执行以下命令修改Docker配置:

    echo '{"max-concurrent-uploads": 1, "timeout": 300}' > /root/.docker/config.json
    

    减少并发上传数并延长超时时间,提升推送稳定性。

  3. 改用ECR跨区域复制
    先将镜像推送到us-east-1的ECR仓库,再通过ECR的跨区域复制功能同步到us-west-1。这种方式利用AWS内部网络,比直接跨区域推送更可靠,只需在源ECR仓库配置复制规则即可。

  4. 检查CodeBuild网络配置
    如果CodeBuild运行在VPC内,确认安全组和路由表允许访问us-west-1的ECR服务。可以临时切换到公共网络环境测试,排除VPC网络限制。

内容的提问来源于stack exchange,提问作者B Randall

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 23:55:54