You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS ECS Fargate服务间通信15秒超时问题排查求助

ECS Fargate服务间请求15秒超时排查

我在AWS ECS Fargate环境中部署了两个服务,它们处于同一VPC的同一子网内。其中一个是监听80端口的ASP.NET Web应用(extension-web-page),另一个服务(web-ui-server)向它发送请求时,客户端会在15秒后取消请求。完全相同的Docker镜像在本地运行无此问题,因此判断是AWS环境配置导致的。查看AWS文档、任务/服务/角色配置后未找到线索,请问这个15秒超时来自哪里?如何延长或消除?

ASP.NET应用日志

2023-12-13T08:46:08.746+01:00   dbug: Microsoft.AspNetCore.Server.Kestrel.Connections[39]
2023-12-13T08:46:08.746+01:00   Connection id "0HMVRLR65I2GS" accepted.
2023-12-13T08:46:08.747+01:00   dbug: Microsoft.AspNetCore.Server.Kestrel.Connections[1]
2023-12-13T08:46:08.747+01:00   Connection id "0HMVRLR65I2GS" started.
2023-12-13T08:46:08.747+01:00   info: Microsoft.AspNetCore.Hosting.Diagnostics[1]
2023-12-13T08:46:08.747+01:00   Request starting HTTP/1.1 POST http://extension-web-page.abtesting/text - application/json 38
2023-12-13T08:46:08.747+01:00   trce: Microsoft.AspNetCore.HostFiltering.HostFilteringMiddleware[2]
2023-12-13T08:46:08.747+01:00   All hosts are allowed.
2023-12-13T08:46:08.747+01:00   dbug: Microsoft.AspNetCore.Routing.Matching.DfaMatcher[1001]
2023-12-13T08:46:08.747+01:00   1 candidate(s) found for the request path '/text'
2023-12-13T08:46:08.747+01:00   dbug: Microsoft.AspNetCore.Routing.EndpointRoutingMiddleware[1]
2023-12-13T08:46:08.747+01:00   Request matched endpoint 'HTTP: POST /text => Text'
2023-12-13T08:46:08.747+01:00   trce: Microsoft.AspNetCore.Routing.EndpointRoutingMiddleware[8]
2023-12-13T08:46:08.747+01:00   The endpoint does not specify the IRequestSizeLimitMetadata.
2023-12-13T08:46:08.748+01:00   info: Microsoft.AspNetCore.Routing.EndpointMiddleware[0]
2023-12-13T08:46:08.748+01:00   Executing endpoint 'HTTP: POST /text => Text'
2023-12-13T08:46:08.748+01:00   dbug: Microsoft.AspNetCore.Server.Kestrel[25]
2023-12-13T08:46:08.748+01:00   Connection id "0HMVRLR65I2GS", Request id "0HMVRLR65I2GS:00000001": started reading request body.
2023-12-13T08:46:08.748+01:00   dbug: Microsoft.AspNetCore.Server.Kestrel[26]
2023-12-13T08:46:08.748+01:00   Connection id "0HMVRLR65I2GS", Request id "0HMVRLR65I2GS:00000001": done reading request body.
2023-12-13T08:46:23.742+01:00   dbug: Microsoft.AspNetCore.Server.Kestrel.Transport.Sockets[6]

**2023-12-13T08:46:23.742+01:00 Connection id "0HMVRLR65I2GS" received FIN.**

2023-12-13T08:46:23.743+01:00   dbug: Microsoft.AspNetCore.Server.Kestrel.Transport.Sockets[7]
2023-12-13T08:46:23.743+01:00   Connection id "0HMVRLR65I2GS" sending FIN because: "The Socket transport's send loop completed gracefully."
2023-12-13T08:46:23.743+01:00   dbug: Microsoft.AspNetCore.Server.Kestrel.Connections[10]
2023-12-13T08:46:23.743+01:00   Connection id "0HMVRLR65I2GS" disconnecting.
2023-12-13T08:47:48.751+01:00   info: Microsoft.AspNetCore.Routing.EndpointMiddleware[1]
2023-12-13T08:47:48.751+01:00   Executed endpoint 'HTTP: POST /text => Text'
2023-12-13T08:47:48.751+01:00   dbug: Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware[4]
2023-12-13T08:47:48.751+01:00   The request was aborted by the client.
2023-12-13T08:47:48.751+01:00   info: Microsoft.AspNetCore.Hosting.Diagnostics[2]
2023-12-13T08:47:48.751+01:00   Request finished HTTP/1.1 POST http://extension-web-page.abtesting/text - 499 - text/plain;+charset=utf-8 100004.1499ms
2023-12-13T08:47:48.751+01:00   dbug: Microsoft.AspNetCore.Server.Kestrel.Connections[2]
2023-12-13T08:47:48.751+01:00   Connection id "0HMVRLR65I2GS" stopped.

CloudFormation配置

Resources:

  # web-ui-server

  WebUiServerTaskDefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      Family: web-ui-server
      NetworkMode: awsvpc
      RequiresCompatibilities:
        - FARGATE
      Cpu: "256"
      Memory: "512"
      ExecutionRoleArn: "arn:aws:iam::XXXXXXXXXXX:role/ecsTaskExecutionRole"
      ContainerDefinitions:
        - Name: web-ui-server
          Image: XXXXXXXXXXX.dkr.ecr.us-east-1.amazonaws.com/web-ui-server:latest
          Essential: true
          PortMappings:
            - ContainerPort: 80
          LogConfiguration:
            LogDriver: "awslogs"
            Options:
              awslogs-create-group: true
              awslogs-group: "/ecs/myproject-dev/web-ui-server/"
              awslogs-region: "us-east-1"
              awslogs-stream-prefix: "ecs"

  WebUiServerService:
    Type: AWS::ECS::Service
    DependsOn: DevMyprojectNLBListener
    Properties:
      ServiceName: web-ui-server
      Cluster: !Ref DevMyprojectECSCluster
      TaskDefinition: !Ref WebUiServerTaskDefinition
      LaunchType: FARGATE
      DesiredCount: 1
      ServiceConnectConfiguration:
        Enabled: true
        Namespace: myproject-dev
      NetworkConfiguration:
        AwsvpcConfiguration:
          Subnets:
            - !Ref DevMyprojectSubnet1
          SecurityGroups:
            - !GetAtt WebUiServerSecurityGroup.GroupId
          AssignPublicIp: ENABLED
      LoadBalancers:
        - ContainerName: web-ui-server
          ContainerPort: 80
          TargetGroupArn: !Ref DevMyprojectTargetGroup

  # extension-web-page

  ExtensionWebPageTaskDefinition:
    Type: AWS::ECS::TaskDefinition
    Properties:
      Family: extension-web-page
      NetworkMode: awsvpc
      RequiresCompatibilities:
        - FARGATE
      Cpu: 256
      Memory: 512
      ExecutionRoleArn: "arn:aws:iam::XXXXXXXXXXX:role/ecsTaskExecutionRole"
      ContainerDefinitions:
        - Name: extension-web-page
          Image: XXXXXXXXXXX.dkr.ecr.us-east-1.amazonaws.com/extension-web-page:latest
          Essential: true
          PortMappings:
            - Name: extension-web-page
              Protocol: tcp
              AppProtocol: http
              ContainerPort: 80
              HostPort: 80
          LogConfiguration:
            LogDriver: "awslogs"
            Options:
              awslogs-create-group: true
              awslogs-group: "/ecs/myproject-dev/extension-web-page/"
              awslogs-region: "us-east-1"
              awslogs-stream-prefix: "ecs"

  ExtensionWebPageService:
    Type: AWS::ECS::Service
    Properties:
      ServiceName: extension-web-page
      Cluster: !Ref DevMyprojectECSCluster
      TaskDefinition: !Ref ExtensionWebPageTaskDefinition
      LaunchType: FARGATE
      DesiredCount: 1
      ServiceConnectConfiguration:
        Enabled: true
        Namespace: myproject-dev
        Services:
        - PortName: extension-web-page
          DiscoveryName: extension-web-page-myproject
          ClientAliases:
          - DnsName: extension-web-page.myproject
            Port: 80
      NetworkConfiguration:
        AwsvpcConfiguration:
          Subnets:
            - !Ref DevMyprojectSubnet1
          SecurityGroups:
            - !GetAtt Subnet1InternalMicroserviceSecurityGroup.GroupId
          AssignPublicIp: ENABLED

  # Security groups

  Subnet1InternalMicroserviceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupName: myproject-dev-subnet1-internal
      GroupDescription: ECSSecurityGroup
      VpcId: !Ref DevMyprojectVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: !Ref DevMyprojectSubnet1Cidr
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 443
          ToPort: 443
          CidrIp: 0.0.0.0/0
          
  WebUiServerSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupName: myproject-dev-web-ui-server
      GroupDescription: ECSSecurityGroup
      VpcId: !Ref DevMyprojectVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 0.0.0.0/0
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 443
          ToPort: 443
          CidrIp: 0.0.0.0/0
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 0.0.0.0/0

排查方向与解决方案

1. ECS ServiceConnect默认超时(最可能原因)

ECS ServiceConnect内部使用Envoy代理,默认请求超时为15秒,这与日志中15秒后收到FIN包的时间完全匹配。

  • 解决:在ExtensionWebPageService的ServiceConnectConfiguration中添加超时配置,自定义请求超时时间(例如设置为60秒):
    Services:
    - PortName: extension-web-page
      DiscoveryName: extension-web-page-myproject
      ClientAliases:
      - DnsName: extension-web-page.myproject
        Port: 80
      Timeout:
        RequestTimeoutSeconds: 60
    

2. 客户端请求超时设置

检查web-ui-server中的HTTP客户端配置,确认是否设置了15秒的请求超时。即使本地环境无问题,AWS环境中可能因代理传递或客户端默认配置触发超时。

  • 解决:调整客户端HTTP请求超时时间,确保大于后端实际处理时间(例如设置为120秒),并与ServiceConnect的超时配置保持一致。

3. Fargate任务资源瓶颈

当前两个任务的CPU配置为256,内存512,如果后端处理需要更多资源,可能导致处理缓慢触发超时。

  • 解决:临时调高任务的CPU和内存配置(例如CPU设为512,内存设为1024),测试是否解决问题,确认资源瓶颈后再调整至合理配置。

4. VPC网络层面排查

AWS VPC默认TCP连接超时为360秒,远大于15秒,因此可能性较低,但可做以下检查:

  • 查看子网对应的网络ACL,确认未设置15秒的TCP连接超时规则;
  • 开启VPC流日志,排查是否存在网络层面的连接中断。

内容的提问来源于stack exchange,提问作者Michael Zelensky

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 02:55:54