AWS ECS Fargate服务间通信15秒超时问题排查求助
ECS Fargate服务间请求15秒超时排查
我在AWS ECS Fargate环境中部署了两个服务,它们处于同一VPC的同一子网内。其中一个是监听80端口的ASP.NET Web应用(extension-web-page),另一个服务(web-ui-server)向它发送请求时,客户端会在15秒后取消请求。完全相同的Docker镜像在本地运行无此问题,因此判断是AWS环境配置导致的。查看AWS文档、任务/服务/角色配置后未找到线索,请问这个15秒超时来自哪里?如何延长或消除?
ASP.NET应用日志
2023-12-13T08:46:08.746+01:00 dbug: Microsoft.AspNetCore.Server.Kestrel.Connections[39] 2023-12-13T08:46:08.746+01:00 Connection id "0HMVRLR65I2GS" accepted. 2023-12-13T08:46:08.747+01:00 dbug: Microsoft.AspNetCore.Server.Kestrel.Connections[1] 2023-12-13T08:46:08.747+01:00 Connection id "0HMVRLR65I2GS" started. 2023-12-13T08:46:08.747+01:00 info: Microsoft.AspNetCore.Hosting.Diagnostics[1] 2023-12-13T08:46:08.747+01:00 Request starting HTTP/1.1 POST http://extension-web-page.abtesting/text - application/json 38 2023-12-13T08:46:08.747+01:00 trce: Microsoft.AspNetCore.HostFiltering.HostFilteringMiddleware[2] 2023-12-13T08:46:08.747+01:00 All hosts are allowed. 2023-12-13T08:46:08.747+01:00 dbug: Microsoft.AspNetCore.Routing.Matching.DfaMatcher[1001] 2023-12-13T08:46:08.747+01:00 1 candidate(s) found for the request path '/text' 2023-12-13T08:46:08.747+01:00 dbug: Microsoft.AspNetCore.Routing.EndpointRoutingMiddleware[1] 2023-12-13T08:46:08.747+01:00 Request matched endpoint 'HTTP: POST /text => Text' 2023-12-13T08:46:08.747+01:00 trce: Microsoft.AspNetCore.Routing.EndpointRoutingMiddleware[8] 2023-12-13T08:46:08.747+01:00 The endpoint does not specify the IRequestSizeLimitMetadata. 2023-12-13T08:46:08.748+01:00 info: Microsoft.AspNetCore.Routing.EndpointMiddleware[0] 2023-12-13T08:46:08.748+01:00 Executing endpoint 'HTTP: POST /text => Text' 2023-12-13T08:46:08.748+01:00 dbug: Microsoft.AspNetCore.Server.Kestrel[25] 2023-12-13T08:46:08.748+01:00 Connection id "0HMVRLR65I2GS", Request id "0HMVRLR65I2GS:00000001": started reading request body. 2023-12-13T08:46:08.748+01:00 dbug: Microsoft.AspNetCore.Server.Kestrel[26] 2023-12-13T08:46:08.748+01:00 Connection id "0HMVRLR65I2GS", Request id "0HMVRLR65I2GS:00000001": done reading request body. 2023-12-13T08:46:23.742+01:00 dbug: Microsoft.AspNetCore.Server.Kestrel.Transport.Sockets[6] **2023-12-13T08:46:23.742+01:00 Connection id "0HMVRLR65I2GS" received FIN.** 2023-12-13T08:46:23.743+01:00 dbug: Microsoft.AspNetCore.Server.Kestrel.Transport.Sockets[7] 2023-12-13T08:46:23.743+01:00 Connection id "0HMVRLR65I2GS" sending FIN because: "The Socket transport's send loop completed gracefully." 2023-12-13T08:46:23.743+01:00 dbug: Microsoft.AspNetCore.Server.Kestrel.Connections[10] 2023-12-13T08:46:23.743+01:00 Connection id "0HMVRLR65I2GS" disconnecting. 2023-12-13T08:47:48.751+01:00 info: Microsoft.AspNetCore.Routing.EndpointMiddleware[1] 2023-12-13T08:47:48.751+01:00 Executed endpoint 'HTTP: POST /text => Text' 2023-12-13T08:47:48.751+01:00 dbug: Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware[4] 2023-12-13T08:47:48.751+01:00 The request was aborted by the client. 2023-12-13T08:47:48.751+01:00 info: Microsoft.AspNetCore.Hosting.Diagnostics[2] 2023-12-13T08:47:48.751+01:00 Request finished HTTP/1.1 POST http://extension-web-page.abtesting/text - 499 - text/plain;+charset=utf-8 100004.1499ms 2023-12-13T08:47:48.751+01:00 dbug: Microsoft.AspNetCore.Server.Kestrel.Connections[2] 2023-12-13T08:47:48.751+01:00 Connection id "0HMVRLR65I2GS" stopped.
CloudFormation配置
Resources: # web-ui-server WebUiServerTaskDefinition: Type: AWS::ECS::TaskDefinition Properties: Family: web-ui-server NetworkMode: awsvpc RequiresCompatibilities: - FARGATE Cpu: "256" Memory: "512" ExecutionRoleArn: "arn:aws:iam::XXXXXXXXXXX:role/ecsTaskExecutionRole" ContainerDefinitions: - Name: web-ui-server Image: XXXXXXXXXXX.dkr.ecr.us-east-1.amazonaws.com/web-ui-server:latest Essential: true PortMappings: - ContainerPort: 80 LogConfiguration: LogDriver: "awslogs" Options: awslogs-create-group: true awslogs-group: "/ecs/myproject-dev/web-ui-server/" awslogs-region: "us-east-1" awslogs-stream-prefix: "ecs" WebUiServerService: Type: AWS::ECS::Service DependsOn: DevMyprojectNLBListener Properties: ServiceName: web-ui-server Cluster: !Ref DevMyprojectECSCluster TaskDefinition: !Ref WebUiServerTaskDefinition LaunchType: FARGATE DesiredCount: 1 ServiceConnectConfiguration: Enabled: true Namespace: myproject-dev NetworkConfiguration: AwsvpcConfiguration: Subnets: - !Ref DevMyprojectSubnet1 SecurityGroups: - !GetAtt WebUiServerSecurityGroup.GroupId AssignPublicIp: ENABLED LoadBalancers: - ContainerName: web-ui-server ContainerPort: 80 TargetGroupArn: !Ref DevMyprojectTargetGroup # extension-web-page ExtensionWebPageTaskDefinition: Type: AWS::ECS::TaskDefinition Properties: Family: extension-web-page NetworkMode: awsvpc RequiresCompatibilities: - FARGATE Cpu: 256 Memory: 512 ExecutionRoleArn: "arn:aws:iam::XXXXXXXXXXX:role/ecsTaskExecutionRole" ContainerDefinitions: - Name: extension-web-page Image: XXXXXXXXXXX.dkr.ecr.us-east-1.amazonaws.com/extension-web-page:latest Essential: true PortMappings: - Name: extension-web-page Protocol: tcp AppProtocol: http ContainerPort: 80 HostPort: 80 LogConfiguration: LogDriver: "awslogs" Options: awslogs-create-group: true awslogs-group: "/ecs/myproject-dev/extension-web-page/" awslogs-region: "us-east-1" awslogs-stream-prefix: "ecs" ExtensionWebPageService: Type: AWS::ECS::Service Properties: ServiceName: extension-web-page Cluster: !Ref DevMyprojectECSCluster TaskDefinition: !Ref ExtensionWebPageTaskDefinition LaunchType: FARGATE DesiredCount: 1 ServiceConnectConfiguration: Enabled: true Namespace: myproject-dev Services: - PortName: extension-web-page DiscoveryName: extension-web-page-myproject ClientAliases: - DnsName: extension-web-page.myproject Port: 80 NetworkConfiguration: AwsvpcConfiguration: Subnets: - !Ref DevMyprojectSubnet1 SecurityGroups: - !GetAtt Subnet1InternalMicroserviceSecurityGroup.GroupId AssignPublicIp: ENABLED # Security groups Subnet1InternalMicroserviceSecurityGroup: Type: AWS::EC2::SecurityGroup Properties: GroupName: myproject-dev-subnet1-internal GroupDescription: ECSSecurityGroup VpcId: !Ref DevMyprojectVPC SecurityGroupIngress: - IpProtocol: tcp FromPort: 80 ToPort: 80 CidrIp: !Ref DevMyprojectSubnet1Cidr SecurityGroupEgress: - IpProtocol: tcp FromPort: 443 ToPort: 443 CidrIp: 0.0.0.0/0 WebUiServerSecurityGroup: Type: AWS::EC2::SecurityGroup Properties: GroupName: myproject-dev-web-ui-server GroupDescription: ECSSecurityGroup VpcId: !Ref DevMyprojectVPC SecurityGroupIngress: - IpProtocol: tcp FromPort: 80 ToPort: 80 CidrIp: 0.0.0.0/0 SecurityGroupEgress: - IpProtocol: tcp FromPort: 443 ToPort: 443 CidrIp: 0.0.0.0/0 - IpProtocol: tcp FromPort: 80 ToPort: 80 CidrIp: 0.0.0.0/0
排查方向与解决方案
1. ECS ServiceConnect默认超时(最可能原因)
ECS ServiceConnect内部使用Envoy代理,默认请求超时为15秒,这与日志中15秒后收到FIN包的时间完全匹配。
- 解决:在
ExtensionWebPageService的ServiceConnectConfiguration中添加超时配置,自定义请求超时时间(例如设置为60秒):Services: - PortName: extension-web-page DiscoveryName: extension-web-page-myproject ClientAliases: - DnsName: extension-web-page.myproject Port: 80 Timeout: RequestTimeoutSeconds: 60
2. 客户端请求超时设置
检查web-ui-server中的HTTP客户端配置,确认是否设置了15秒的请求超时。即使本地环境无问题,AWS环境中可能因代理传递或客户端默认配置触发超时。
- 解决:调整客户端HTTP请求超时时间,确保大于后端实际处理时间(例如设置为120秒),并与ServiceConnect的超时配置保持一致。
3. Fargate任务资源瓶颈
当前两个任务的CPU配置为256,内存512,如果后端处理需要更多资源,可能导致处理缓慢触发超时。
- 解决:临时调高任务的CPU和内存配置(例如CPU设为512,内存设为1024),测试是否解决问题,确认资源瓶颈后再调整至合理配置。
4. VPC网络层面排查
AWS VPC默认TCP连接超时为360秒,远大于15秒,因此可能性较低,但可做以下检查:
- 查看子网对应的网络ACL,确认未设置15秒的TCP连接超时规则;
- 开启VPC流日志,排查是否存在网络层面的连接中断。
内容的提问来源于stack exchange,提问作者Michael Zelensky
相关产品推荐
相关产品推荐

