ECS Fargate任务定义报错:不支持sourcePath,移除兼容配置仍异常
问题描述
在AWS ECS Fargate上部署Datadog Agent时遇到两个矛盾错误:
- 任务定义添加
requires_compatibilities = ["FARGATE"]时,报错:ClientException: Fargate compatible task definitions do not support sourcePath - 移除该配置后,启动服务时报错:
Task definition does not support launch_type FARGATE
以下是当前使用的配置文件:
Terraform配置
resource "aws_ecs_task_definition" "datadog" { family = "project-datadog-ecs" requires_compatibilities = ["FARGATE"] network_mode = "awsvpc" cpu = "2048" memory = "8192" execution_role_arn = aws_iam_role.ecs_tasks_execution_role.arn container_definitions = file("${path.module}/datadog-agent-ecs-logs.json") volume { host_path = "/var/run/docker.sock" name = "docker_sock" } volume { host_path = "/proc/" name = "proc" } volume { host_path = "/sys/fs/cgroup/" name = "cgroup" } volume { host_path = "/opt/datadog-agent/run" name = "pointdir" } volume { host_path = "/var/lib/docker/containers/" name = "containers_root" } tags = local.mandatory_tags } resource "aws_ecs_service" "datadog" { name = "project-datadog" cluster = module.ecs_cluster.cluster_id task_definition = aws_ecs_task_definition.datadog.arn desired_count = 1 tags = local.mandatory_tags }
容器定义JSON(datadog-agent-ecs-logs.json)
[ { "name": "datadog-agent", "image": "public.ecr.aws/datadog/agent:latest", "cpu": 100, "memory": 512, "essential": true, "healthCheck": { "retries": 3, "command": ["CMD-SHELL","agent health"], "timeout": 5, "interval": 30, "startPeriod": 15 }, "mountPoints": [ { "containerPath": "/var/run/docker.sock", "sourceVolume": "docker_sock", "readOnly": null }, { "containerPath": "/host/sys/fs/cgroup", "sourceVolume": "cgroup", "readOnly": null }, { "containerPath": "/host/proc", "sourceVolume": "proc", "readOnly": null }, { "containerPath": "/opt/datadog-agent/run", "sourceVolume": "pointdir", "readOnly": false }, { "containerPath": "/var/lib/docker/containers", "sourceVolume": "containers_root", "readOnly": true } ], "environment": [ { "name": "DD_API_KEY", "value": "API" }, { "name": "DD_SITE", "value": "SITE" }, { "name": "DD_LOGS_ENABLED", "value": "true" }, { "name": "DD_LOGS_CONFIG_CONTAINER_COLLECT_ALL", "value": "true" } ] } ]
解决方案
核心原因
Fargate是无服务器容器运行环境,不允许挂载主机节点的文件系统路径(即host_path类型的卷),这是第一个错误的根源;而第二个错误是因为任务定义必须明确声明兼容Fargate,才能使用Fargate启动类型。
调整配置步骤
移除所有
host_path类型的卷定义
删掉Terraform任务定义里的所有volume块,Fargate不支持此类挂载。修改容器定义,删除无用挂载点
移除容器定义中所有对应主机路径卷的mountPoints条目,Datadog Agent在Fargate环境中不需要挂载docker.sock、proc、cgroup等主机路径,可通过ECS任务元数据端点获取所需信息。添加Fargate专用环境变量
调整Agent的环境变量,适配Fargate运行环境:DD_ECS_FARGATE=true:告知Agent当前运行在Fargate环境DD_LOGS_CONFIG_USE_ECS_LOG_METADATA=true:通过ECS元数据收集容器日志,替代挂载日志目录的方式DD_PROCESS_AGENT_ENABLED=false:Fargate不支持进程代理,必须禁用
修改后的配置示例
Terraform任务定义
resource "aws_ecs_task_definition" "datadog" { family = "project-datadog-ecs" requires_compatibilities = ["FARGATE"] network_mode = "awsvpc" cpu = "2048" memory = "8192" execution_role_arn = aws_iam_role.ecs_tasks_execution_role.arn container_definitions = file("${path.module}/datadog-agent-fargate.json") tags = local.mandatory_tags } resource "aws_ecs_service" "datadog" { name = "project-datadog" cluster = module.ecs_cluster.cluster_id task_definition = aws_ecs_task_definition.datadog.arn desired_count = 1 launch_type = "FARGATE" network_configuration { subnets = module.vpc.private_subnets security_groups = [aws_security_group.datadog_agent.id] assign_public_ip = false # 根据实际网络配置调整 } tags = local.mandatory_tags }
容器定义JSON(datadog-agent-fargate.json)
[ { "name": "datadog-agent", "image": "public.ecr.aws/datadog/agent:latest", "cpu": 100, "memory": 512, "essential": true, "healthCheck": { "retries": 3, "command": ["CMD-SHELL","agent health"], "timeout": 5, "interval": 30, "startPeriod": 15 }, "environment": [ { "name": "DD_API_KEY", "value": "API" }, { "name": "DD_SITE", "value": "SITE" }, { "name": "DD_LOGS_ENABLED", "value": "true" }, { "name": "DD_ECS_FARGATE", "value": "true" }, { "name": "DD_LOGS_CONFIG_USE_ECS_LOG_METADATA", "value": "true" }, { "name": "DD_PROCESS_AGENT_ENABLED", "value": "false" } ] } ]
额外注意事项
- 确保ECS执行角色拥有访问ECS元数据、CloudWatch日志(若收集CloudWatch日志)以及Datadog API的权限
- 若需要更灵活的日志收集方案,可使用FireLens作为日志路由器,直接将容器日志发送至Datadog
内容的提问来源于stack exchange,提问作者TukTuk
相关产品推荐
相关产品推荐

